Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 2021-0115 Moderate: pngcheck Buffer Overrun Security Issue

mageia
Calendar Grey March 5, 2021
Dist Mageia Esm H88
Mageia 2021-0116 resolves critical vulnerabilities in libpng that could lead to security breaches. Review the patch notes for further information.
This update fixes a buffer-overrun bug related to the MNG LOOP chunk (which gets noticed even in PNG files if the -s option is used)

Summary

This update fixes a buffer-overrun bug related to the MNG LOOP chunk (which gets noticed even in PNG files if the -s option is used). (RHBZ#1908559). It also fixes a buffer overrun for certain invalid MNG PPLT chunk contents.

References

- https://bugs.mageia.org/show_bug.cgi?id=28331

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/XTD56567QSWLCTKBJNTCF6HB5GLJZCHX/

Resolution

SRPMS

- 8/core/pngcheck-3.0.2-1.mga8

- 7/core/pngcheck-3.0.2-1.mga7

Publication date: 05 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0115.html
Type: security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here