LWN.net Logo

libpng: resource consumption

Package(s):libpng10 CVE #(s):CVE-2010-0205
Created:March 16, 2010 Updated:October 6, 2010
Description: From the Red Hat bugzilla:

It was reported that libpng suffers from an issue where certain highly compressed ancillary chunks (zTxt, iTxt, iCCP) could cause libpng to stall or crash by consuming huge amounts of memory. This vulnerability is reported to affect all versions of libpng prior to 1.4.1, as well as versions of Firefox from 3.0. It is also possible that other gecko-based browsers are vulnerable as well, as well as all versions of pngcrush, ImageMagick, and GraphicsMagick.

Alerts:
Gentoo 201010-01 2010-10-05
CentOS CESA-2010:0534 2010-08-16
CentOS CESA-2010:0534 2010-07-21
Fedora FEDORA-2010-10833 2010-07-06
CentOS CESA-2010:0534 2010-07-14
CentOS CESA-2010:0534 2010-07-21
Red Hat RHSA-2010:0534-01 2010-07-14
SuSE SUSE-SR:2010:012 2010-05-25
SuSE SUSE-SR:2010:011 2010-05-10
SuSE SUSE-SR:2010:013 2010-06-14
Debian DSA-2032-1 2010-04-11
Pardus 2010-41 2010-03-29
Fedora FEDORA-2010-4616 2010-03-16
Fedora FEDORA-2010-4673 2010-03-16
Mandriva MDVSA-2010:064 2010-03-23
Mandriva MDVSA-2010:063 2010-03-22
Ubuntu USN-913-1 2010-03-16
Fedora FEDORA-2010-3414 2010-03-03
Fedora FEDORA-2010-3375 2010-03-03
Oracle ELSA-2012-0317 2012-02-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds