[Ximian Updates] libpng has a potential buffer overflow when loading progressive images

Ximian GNOME Security Team <[email protected]> Tue, 6 Aug 2002 17:06:12 -0400
Newsgroups gmane.comp.gnome.ximian.updates
Message-ID <[email protected]>
Severity: Security
Product: libpng
Keywords: Red Carpet libpng buffer overflow
URL: http://support.ximian.com/q?283
References: 
Release Notes for libpng 
ftp://swrinde.nde.swri.edu/pub/png-group/archives/png-list.200207

libpng is a library used to create and manipulate PNG (Portable
Network Graphics) image files.

The 1.2.4* and 1.0.14 releases of libpng solve a potential buffer
overflow vulnerability[1] in some functions related to progressive
image loading. Programs such as mozilla and various others use these
functions. An attacker could exploit this to remotely run arbitrary
code or crash an application by using a specially crafted png image.

These new releases also solve other minor bugs such as some memory
leaks in reading image functions.

Since most applications which display images use libpng, this affects
many applications including Evolution and Mozilla. Additionally, Red
Carpet links libpng statically and needs to be updated separately.

Ximian only ships libpng on Solaris, and so we only have Solaris
packages available. When distribution vendors update their packages,
they will be available in Red Carpet. Please use Red Carpet to upgrade
libpng to 1.0.14 and Red Carpet 1.3.4-2. You can also get packages
from the Ximian FTP site:

Solaris 7/8
ftp://ftp.ximian.com/pub/ximian-gnome/solaris-7-sun4/libpng-1.0.14-1.ximian.1.sparc.rpm
ftp://ftp.ximian.com/pub/ximian-gnome/solaris-7-sun4/libpng-devel-1.0.14-1.ximian.1.sparc.rpm
ftp://ftp.ximian.com/pub/ximian-gnome/solaris-7-sun4/red-carpet-1.3.4-2.ximian.1.sparc.rpm



_______________________________________________
updates maillist  -  [email protected]
http://lists.ximian.com/mailman/listinfo/updates
Please DO NOT reply to this list!  Use [email protected] or [email protected] instead.