Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Gentoo: GLSA-200603-18 Moderate: Pngcrush Buffer Overflow Threat

gentoo
Calendar Grey March 21, 2006
Scroller Gentoo
The recent GLSA-202201-03 from Gentoo highlights a significant buffer overflow vulnerability found in the library LibXYZ, potentially allowing arbitrary code execution.
Pngcrush is vulnerable to a buffer overflow which could potentially lead to the execution of arbitrary code.

Summary

Gentoo Linux Security Advisory GLSA 200603-18 https://security.gentoo.org/ Severity: Normal Title: Pngcrush: Buffer overflow Date: March 21, 2006 Bugs: #123286 ID: 200603-18

Synopsis ======= Pngcrush is vulnerable to a buffer overflow which could potentially lead to the execution of arbitrary code.
Background ========= Pngcrush is an optimizer for PNG files.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/pngcrush < 1.6.2 >= 1.6.2
========== Carsten Lohrke of Gentoo Linux reported that Pngcrush contains a vulnerable version of zlib (GLSA 200507-19).
Impact ===== By creating a specially crafted data stream, attackers can overwrite data stru...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround