Fwd: [suse-security-announce] SuSE Security Announcement: libpng (SuSE-SA:2003:0004)

Dan Osterrath <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I just quote the mail from the SuSE security list:


                        SuSE Security Announcement

        Package:                libpng
        Announcement-ID:        SuSE-SA:2003:0004
        Date:                   Tuesday, Jan 14th 2003 11:00 MEST
        Affected products:      7.1, 7.2, 7.3, 8.0, 8.1
                                SuSE Linux Database Server
                                SuSE eMail Server 3.1
                                SuSE eMail Server III
                                SuSE Firewall Adminhost VPN
                                SuSE Linux Admin-CD for Firewall
                                SuSE Firewall on CD 2 - VPN
                                SuSE Firewall on CD 2
                                SuSE Linux Enterprise Server for S/390
                                SuSE Linux Connectivity Server
                                SuSE Linux Enterprise Server 7
                                SuSE Linux Enterprise Server 8
                                SuSE Linux Office Server
                                UnitedLinux 1.0
        Vulnerability Type:     possible remote compromise
        Severity (1-10):        4
        SuSE default package:   yes
        Cross References:       CAN-2002-1363

    Content of this advisory:
        1) security vulnerability resolved: wrong offset calculation
           problem description, discussion, solution and upgrade information
        2) pending vulnerabilities, solutions, workarounds:
            - fam
            - xpdf
            - libmcrypt
        3) standard appendix (further information)

_____________________________________________________________________________
_

1)  problem description, brief discussion, solution, upgrade information

    The library libpng provides several functions to encode, decode and
    manipulate Portable Network Graphics (PNG) image files.
    Due to wrong calculation of some loop offset values a buffer overflow
    can occur. The buffer overflow can lead to Denial-of-Service or even
    to remote compromise.

    After updating libpng all applications that use libpng should be
    restarted. Due to the fact that a lot of applications are linked
    with libpng it may be necessary to switch to runlevel S and back
    to the previous runlevel or even to reboot the system.

    There is no temporary fix known. Please install the new packages from
    our FTP servers.

    Please download the update package for your distribution and verify its
    integrity by the methods listed in section 3) of this announcement.
    Then, install the package using the command "rpm -Fhv file.rpm" to apply
    the update.
    Our maintenance customers are being notified individually. The packages
    are being offered to install from the maintenance web.
_____________________________________________________________________________
_

2)  Pending vulnerabilities in SuSE Distributions and Workarounds:

    - fam
      SuSE Versions < 8.0 are shipping a vulnerable version of fam
      which allows unprivileged users to determine filenames of
      group root.
      New fam packages are build and will be released right after
      quality assurance permits.
    - xpdf
      An integer overflow in pdftops may lead to system compromise.
      New packages are currently being build.
    - libmcrypt
      Several buffer overflows in libmcrypt were discovered by Ilia
      Alshanetsky. The buffer overflows can lead to system compromise.
      New packages are currently being build.


_____________________________________________________________________________
_

- -- 
- ----------------------------------------------------------------------
%> ln -s /dev/null /dev/brain
%> ln -s /dev/urandom /dev/world
%> dd if=/dev/world of=/dev/brain
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQE+I+jN9NbB8EM160MRAn3OAKCtCyG2Jvu4a3xG5T3kVVySTqoBxgCeNQG8
7ZD0ub3WCkxYDULEjcn7uzg=
=kpjE
-----END PGP SIGNATURE-----

-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.