Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 10: 2009-6128 High: pnglib Buffer Overflow Vulnerabilities

fedora
Calendar Grey May 18, 2009
Dist Fedora Esm H88
Important Fedora 9 patch for giflib addresses potential NULL pointer dereference and memory corruption vulnerabilities impacting GIF handling.
- CVE-2005-2974: NULL pointer dereference crash (#494826) - CVE-2005-3350: Memory corruption via a crafted GIF (#494823) - Solved multilib problems with documentation (#465208, ...

Summary

The giflib package contains a shared library of functions for loading and

saving GIF format image files. It is API and ABI compatible with libungif,

the library which supported uncompressed GIFs while the Unisys LZW patent

was in effect.

Update Information:

- CVE-2005-2974: NULL pointer dereference crash (#494826) - CVE-2005-3350: Memory corruption via a crafted GIF (#494823) - Solved multilib problems with documentation (#465208, #474538) - Removed static library from giflib-devel package (#225796 #c1)

Change Log

* Sat May 16 2009 Robert Scheck 4.1.3-10 - CVE-2005-2974: NULL pointer dereference crash (#494826) - CVE-2005-3350: Memory corruption via a crafted GIF (#494823) - Solved multilib problems with documentation (#465208, #474538) - Removed static library from giflib-devel package (#225796 #c1)

References


[ 1 ] Bug #494826 - CVE-2005-2974 giflib/libunfig: NULL pointer dereference crash https://bugzilla.redhat.com/show_bug.cgi?id=494826 [ 2 ] Bug #494823 - CVE-2005-3350 giflib/libunfig: memory corruption via a crafted GIF https://bugzilla.redhat.com/show_bug.cgi?id=494823

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update giflib' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: giflib
Product: Fedora 9
Version: 4.1.3
Release: 10.fc9
Summary: Library for manipulating GIF format image files

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here