[Ximian Updates] libpng has a potential buffer overflow when loading progressive images
Ximian GNOME Security Team <[email protected]> Tue, 6 Aug 2002 17:06:12 -0400
| Newsgroups | gmane.comp.gnome.ximian.updates |
|---|---|
| Message-ID | <[email protected]> |
Severity: Security Product: libpng Keywords: Red Carpet libpng buffer overflow URL: http://support.ximian.com/q?283 References: Release Notes for libpng ftp://swrinde.nde.swri.edu/pub/png-group/archives/png-list.200207 libpng is a library used to create and manipulate PNG (Portable Network Graphics) image files. The 1.2.4* and 1.0.14 releases of libpng solve a potential buffer overflow vulnerability[1] in some functions related to progressive image loading. Programs such as mozilla and various others use these functions. An attacker could exploit this to remotely run arbitrary code or crash an application by using a specially crafted png image. These new releases also solve other minor bugs such as some memory leaks in reading image functions. Since most applications which display images use libpng, this affects many applications including Evolution and Mozilla. Additionally, Red Carpet links libpng statically and needs to be updated separately. Ximian only ships libpng on Solaris, and so we only have Solaris packages available. When distribution vendors update their packages, they will be available in Red Carpet. Please use Red Carpet to upgrade libpng to 1.0.14 and Red Carpet 1.3.4-2. You can also get packages from the Ximian FTP site: Solaris 7/8 ftp://ftp.ximian.com/pub/ximian-gnome/solaris-7-sun4/libpng-1.0.14-1.ximian.1.sparc.rpm ftp://ftp.ximian.com/pub/ximian-gnome/solaris-7-sun4/libpng-devel-1.0.14-1.ximian.1.sparc.rpm ftp://ftp.ximian.com/pub/ximian-gnome/solaris-7-sun4/red-carpet-1.3.4-2.ximian.1.sparc.rpm _______________________________________________ updates maillist - [email protected] http://lists.ximian.com/mailman/listinfo/updates Please DO NOT reply to this list! Use [email protected] or [email protected] instead.