LWN.net Logo

libglpng: arbitrary code execution

Package(s):libglpng CVE #(s):CVE-2010-1519
Created:September 13, 2010 Updated:September 15, 2010
Description: From the CVE entry:

Multiple integer overflows in glpng.c in glpng 1.45 allow context-dependent attackers to execute arbitrary code via a crafted PNG image, related to (1) the pngLoadRawF function and (2) the pngLoadF function, leading to heap-based buffer overflows.

Alerts:
Mandriva MDVSA-2010:179 2010-09-12
Fedora FEDORA-2010-14525 2010-09-11
Fedora FEDORA-2010-14529 2010-09-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds