LWN.net Logo

optipng: use after free

Package(s):optipng CVE #(s):
Created:October 31, 2012 Updated:October 31, 2012
Description: From the optipng changelog:

Version 0.7.3 fixed a use-after-free vulnerability in the palette reduction code. This vulnerability was accidentally introduced in version 0.7.

Version 0.7.4 fixed the previous fix, which failed to fix the option -fix. (Thanks to Gynvael Coldwind and Mateusz Jurczyk for the report.)

Alerts:
Fedora FEDORA-2012-16680 2012-10-31

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds