libpng-1.2.35 and libpng-1.0.43 fix security vulnerability
Glenn Randers-Pehrson <[email protected]> Wed, 18 Feb 2009 20:26:25 -0500
| Newsgroups | gmane.comp.graphics.png.announce |
|---|---|
| Message-ID | <e56ccc8f0902181726i200f4bf0n20d919473ec409b7__2593.9633873806$1235006919$gmane$org@mail.gmail.com> |
Libpng-1.0.43 and libpng-1.2.35 are available from ftp://ftp.simplesystems.org/pub/png/src and from http://libpng.sf.net These fix a vulnerability reported by Tavis Ormandy in which some arrays of pointers are not initialized prior to using "malloc" to define the pointers. If the application runs out of memory, then libpng's cleanup process will try to free all of the pointers in the array, some of which are not initialized. For more details, and a patch for older libpng versions, see libpng-1.2.34-ADVISORY.txt that is included in the libpng-1.2.35 distribution. Glenn ------------------------------------------------------------------------------ Open Source Business Conference (OSBC), March 24-25, 2009, San Francisco, CA -OSBC tackles the biggest issue in open source: Open Sourcing the Enterprise -Strategies to boost innovation and cut costs with open source participation -Receive a $600 discount off the registration fee with the source code: SFAD http://p.sf.net/sfu/XcvMzF8H