Jump to content

Advisories MDVSA-2010:064: libpng


paul
 Share

Recommended Posts

A vulnerability has been found and corrected in libpng:

 

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before

1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly

handle compressed ancillary-chunk data that has a disproportionately

large uncompressed representation, which allows remote attackers to

cause a denial of service (memory and CPU consumption, and application

hang) via a crafted PNG file, as demonstrated by use of the deflate

compression method on data composed of many occurrences of the same

character, related to a decompression bomb attack (CVE-2010-0205).

 

The updated packages have been patched to correct this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...