Description
Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers.
Affected products
- greg_roelofs / libpng1.0.5 – 1.0.5
- greg_roelofs / libpng1.0.6 – 1.0.6
- greg_roelofs / libpng1.0.7 – 1.0.7
- greg_roelofs / libpng1.0.8 – 1.0.8
- greg_roelofs / libpng1.0.9 – 1.0.9
- greg_roelofs / libpng1.0.11 – 1.0.11
- greg_roelofs / libpng1.0.12 – 1.0.12
- greg_roelofs / libpng1.0.13 – 1.0.13
- greg_roelofs / libpng1.0.14 – 1.0.14
- greg_roelofs / libpng1.2.0 – 1.2.0
- greg_roelofs / libpng1.2.1 – 1.2.1
- greg_roelofs / libpng1.2.2 – 1.2.2
- greg_roelofs / libpng1.2.3 – 1.2.3
- greg_roelofs / libpng1.2.4 – 1.2.4
References
- MISChttp://www.redhat.com/support/errata/RHSA-2004-402.html
- MISChttps://bugzilla.fedora.us/show_bug.cgi?id=1943
- MISChttp://www.securityfocus.com/bid/6431
- MISChttp://www.redhat.com/support/errata/RHSA-2003-007.html
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3657
- VENDOR_ADVISORYhttp://www.debian.org/security/2002/dsa-213
- MISChttp://www.redhat.com/support/errata/RHSA-2003-157.html
- VENDOR_ADVISORYhttp://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:008
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/10925
- VENDOR_ADVISORYhttp://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:063
- MISChttp://www.redhat.com/support/errata/RHSA-2003-119.html
- MISChttp://www.redhat.com/support/errata/RHSA-2004-249.html
- MISChttp://www.redhat.com/support/errata/RHSA-2003-006.html
- VENDOR_ADVISORYhttp://www.novell.com/linux/security/advisories/2003_004_libpng.html