LWN.net Logo

libpng: denial of service

Package(s):libpng CVE #(s):CVE-2008-1382
Created:April 15, 2008 Updated:June 18, 2009
Description: From the CVE entry: libpng 1.0.6 through 1.0.32, 1.2.0 through 1.2.26, and 1.4.0beta01 through 1.4.0beta19 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PNG file with zero length "unknown" chunks, which trigger an access of uninitialized memory.
Alerts:
Fedora FEDORA-2009-6603 2009-06-18
Debian DSA-1750-1 2009-03-22
Ubuntu USN-730-1 2009-03-06
CentOS CESA-2009:0333 2009-03-05
Red Hat RHSA-2009:0333-01 2009-03-04
Fedora FEDORA-2009-2128 2009-02-26
Gentoo 200812-15 2008-12-14
Fedora FEDORA-2008-9379 2008-11-13
Fedora FEDORA-2008-9393 2008-11-13
Mandriva MDVSA-2008:156 2007-07-28
Fedora FEDORA-2008-4910 2008-06-03
Fedora FEDORA-2008-4847 2008-06-03
Fedora FEDORA-2008-4947 2008-06-03
Fedora FEDORA-2008-3683 2008-05-28
Fedora FEDORA-2008-3937 2008-05-28
Fedora FEDORA-2008-3979 2008-05-28
Gentoo 200805-10 2008-05-11
rPath rPSA-2008-0151-1 2008-04-29
Slackware SSA:2008-119-01 2008-04-29
SuSE SUSE-SR:2008:010 2008-04-25
Gentoo 200804-15 2008-04-15
Oracle ELSA-2012-0317 2012-02-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds