Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 7 and 8 MGASA-2021-0210 Moderate: Pngcheck Crash Bug Fix

mageia
Calendar Grey May 12, 2021
Dist Mageia Esm H88
MGASA-2021-0211 security update for zlib addresses a buffer overflow vulnerability that can be triggered through the manipulation of compressed data.
This update fixes a divide-by-zero crash bug (and probable vulnerability) in interlaced images with extra compressed data beyond the nominal end of the image data

Summary

This update fixes a divide-by-zero crash bug (and probable vulnerability) in interlaced images with extra compressed data beyond the nominal end of the image data. (found by "chiba of topsec alpha lab") (rhbz#1949800). References:

References

- https://bugs.mageia.org/show_bug.cgi?id=28879

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DGE643ALPDU76YXVRUPIB5FNWLYX3PXF/

Resolution

SRPMS

- 8/core/pngcheck-3.0.3-1.mga8

- 7/core/pngcheck-3.0.3-1.mga7

Publication date: 12 May 2021
URL: https://advisories.mageia.org/MGASA-2021-0210.html
Type: security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here