LWN.net Logo

libpng: integer overflows

Package(s):libpng CVE #(s):CAN-2004-0955
Created:October 20, 2004 Updated:October 25, 2004
Description: A new set of integer overflows has been found in the libpng library; these overflows could perhaps be exploited (by way of a malicious image file) to execute arbitrary code.
Alerts:
Ubuntu USN-1-1 2004-10-22
Debian DSA-571-1 2004-10-20
Debian DSA-570-1 2004-10-20

(Log in to post comments)

libpng: integer overflows

Posted Oct 23, 2004 2:22 UTC (Sat) by roelofs (guest, #2599) [Link]

These are not new (except apparently to Debian); they're exactly the same overflows identified in July and fixed by most vendors (and the libpng team) in early August. See the png-implement archives for the definitive statement by the libpng maintainer.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds