MGASA-2021-0115 - Updated pngcheck packages fix security vulnerabilities

Publication date: 05 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0115.html
Type: security
Affected Mageia releases: 7, 8

This update fixes a buffer-overrun bug related to the MNG LOOP chunk
(which gets noticed even in PNG files if the -s option is used).
(RHBZ#1908559).

It also fixes a buffer overrun for certain invalid MNG PPLT chunk contents.
(RHBZ#1907428).

References:
- https://bugs.mageia.org/show_bug.cgi?id=28331
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/XTD56567QSWLCTKBJNTCF6HB5GLJZCHX/

SRPMS:
- 8/core/pngcheck-3.0.2-1.mga8
- 7/core/pngcheck-3.0.2-1.mga7

Mageia 2021-0115: pngcheck security update

This update fixes a buffer-overrun bug related to the MNG LOOP chunk (which gets noticed even in PNG files if the -s option is used)

Summary

This update fixes a buffer-overrun bug related to the MNG LOOP chunk (which gets noticed even in PNG files if the -s option is used). (RHBZ#1908559). It also fixes a buffer overrun for certain invalid MNG PPLT chunk contents.

References

- https://bugs.mageia.org/show_bug.cgi?id=28331

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/XTD56567QSWLCTKBJNTCF6HB5GLJZCHX/

Resolution

MGASA-2021-0115 - Updated pngcheck packages fix security vulnerabilities

SRPMS

- 8/core/pngcheck-3.0.2-1.mga8

- 7/core/pngcheck-3.0.2-1.mga7

Severity
Publication date: 05 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0115.html
Type: security

Related News