Jump to content

Advisories MDVSA-2010:063: libpng


paul
 Share

Recommended Posts

Multiple vulnerabilities has been found and corrected in libpng:

 

libpng before 1.2.37 does not properly parse 1-bit interlaced images

with width values that are not divisible by 8, which causes libpng

to include uninitialized bits in certain rows of a PNG file and

might allow remote attackers to read portions of sensitive memory

via out-of-bounds pixels in the file (CVE-2009-2042).

 

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before

1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly

handle compressed ancillary-chunk data that has a disproportionately

large uncompressed representation, which allows remote attackers to

cause a denial of service (memory and CPU consumption, and application

hang) via a crafted PNG file, as demonstrated by use of the deflate

compression method on data composed of many occurrences of the same

character, related to a decompression bomb attack (CVE-2010-0205).

 

Packages for 2008.0 are provided for Corporate Desktop 2008.0

customers.

 

The updated packages have been patched to correct these issues.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...