Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Gentoo: 2003-01-08 Buffer Overflow Remote Exploit for Libpng

gentoo
Calendar Grey January 8, 2003
Dist Gentoo Esm H88
- -------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNC
There is a problem in connection with 16-bit samples from libpng.

Summary


- --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200301-7
- --------------------------------------------------------------------
DATE    : 2003-01-08 15:01 UTC

- --------------------------------------------------------------------
From Debian Security Advisory DSA 213-1:
"Glenn Randers-Pehrson discovered a problem in connection with 16-bit samples from libpng, an interface for reading and writing PNG (Portable Network Graphics) format files. The starting offsets for the loops are calculated incorrectly which causes a buffer overrun beyond the beginning of the row buffer."
Read the full advisory at https://www.debian.org/
SOLUTION
It is recommended that all Gentoo Linux users who are running media-libs/libpng-1.2.5-r1 or earlier update their systems as follows:
emerge rsync emerge libpng
If you also have libpng-1.0.12-r1 or earlier installed update your system as follows:
emerge \=media-libs/libpng-1.0.12-r2
Finish with:
em...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : libpng
SUMMARY : buffer overflow
EXPLOIT : remote

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here