Fwd: [suse-security-announce] SuSE Security Announcement: libpng (SuSE-SA:2003:0004)
Dan Osterrath <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
I just quote the mail from the SuSE security list:
SuSE Security Announcement
Package: libpng
Announcement-ID: SuSE-SA:2003:0004
Date: Tuesday, Jan 14th 2003 11:00 MEST
Affected products: 7.1, 7.2, 7.3, 8.0, 8.1
SuSE Linux Database Server
SuSE eMail Server 3.1
SuSE eMail Server III
SuSE Firewall Adminhost VPN
SuSE Linux Admin-CD for Firewall
SuSE Firewall on CD 2 - VPN
SuSE Firewall on CD 2
SuSE Linux Enterprise Server for S/390
SuSE Linux Connectivity Server
SuSE Linux Enterprise Server 7
SuSE Linux Enterprise Server 8
SuSE Linux Office Server
UnitedLinux 1.0
Vulnerability Type: possible remote compromise
Severity (1-10): 4
SuSE default package: yes
Cross References: CAN-2002-1363
Content of this advisory:
1) security vulnerability resolved: wrong offset calculation
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds:
- fam
- xpdf
- libmcrypt
3) standard appendix (further information)
_____________________________________________________________________________
_
1) problem description, brief discussion, solution, upgrade information
The library libpng provides several functions to encode, decode and
manipulate Portable Network Graphics (PNG) image files.
Due to wrong calculation of some loop offset values a buffer overflow
can occur. The buffer overflow can lead to Denial-of-Service or even
to remote compromise.
After updating libpng all applications that use libpng should be
restarted. Due to the fact that a lot of applications are linked
with libpng it may be necessary to switch to runlevel S and back
to the previous runlevel or even to reboot the system.
There is no temporary fix known. Please install the new packages from
our FTP servers.
Please download the update package for your distribution and verify its
integrity by the methods listed in section 3) of this announcement.
Then, install the package using the command "rpm -Fhv file.rpm" to apply
the update.
Our maintenance customers are being notified individually. The packages
are being offered to install from the maintenance web.
_____________________________________________________________________________
_
2) Pending vulnerabilities in SuSE Distributions and Workarounds:
- fam
SuSE Versions < 8.0 are shipping a vulnerable version of fam
which allows unprivileged users to determine filenames of
group root.
New fam packages are build and will be released right after
quality assurance permits.
- xpdf
An integer overflow in pdftops may lead to system compromise.
New packages are currently being build.
- libmcrypt
Several buffer overflows in libmcrypt were discovered by Ilia
Alshanetsky. The buffer overflows can lead to system compromise.
New packages are currently being build.
_____________________________________________________________________________
_
- --
- ----------------------------------------------------------------------
%> ln -s /dev/null /dev/brain
%> ln -s /dev/urandom /dev/world
%> dd if=/dev/world of=/dev/brain
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)
iD8DBQE+I+jN9NbB8EM160MRAn3OAKCtCyG2Jvu4a3xG5T3kVVySTqoBxgCeNQG8
7ZD0ub3WCkxYDULEjcn7uzg=
=kpjE
-----END PGP SIGNATURE-----
--
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message