It is currently Wed Jun 19, 2013 10:56 pm

All times are UTC




Post new topic Reply to topic  [ 5 posts ] 
Author Message
 Post subject: [Fixed]CVE-2008-3964(libpng 1.2.x)
PostPosted: Fri Sep 12, 2008 2:10 am 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
CVE-2008-3964 wrote:
Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the png_push_read_zTXt function in pngread.c, and possibly related to (2) pngtest.c.


It looks like libpng is in trouble again, we currently use Slackware's package (ver. 1.2.27). Last time I created a ZENBUILD in order to generate a quick security fixes before new SlackBuild was out. Maybe we can do it again... :-\

!8! !8! !8!


Last edited by infwonder on Wed Dec 17, 2008 1:01 am, edited 1 time in total.

 Profile Send private message  
 
 Post subject: Re: [CVE-2008-3964]libpng 1.2.x<1.2.32beta01, Denial of service
PostPosted: Mon Oct 27, 2008 2:41 pm 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
There is another remote DoS found in libpng, the developing team has released version 1.2.33rc02 to fix teh issue:

Secunia.com wrote:

Description:
A vulnerability has been reported in libpng, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to a memory leak error within the "png_handle_tEXt()" function in pngrutil.c. This can be exploited to potentially exhaust all available memory via a specially crafted PNG image.

The vulnerability is reported in version 1.2.32. Other versions may also be affected.

Solution:
Fixed in version 1.2.33rc02.

Provided and/or discovered by:
Reported by the vendor.


Reference:
http://secunia.com/Advisories/32418/


 Profile Send private message  
 
 Post subject: Re: [CVE-2008-3964]libpng 1.2.x<1.2.32beta01, Denial of service
PostPosted: Thu Nov 13, 2008 1:25 am 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
There is yet another issue in libpng again...

According to the release note of libpng 1.2.33rc02:
http://sourceforge.net/project/shownote ... up_id=5624

and the report on SecurityFocus:

SecurityFocus wrote:
The 'libpng' library is prone to a remote denial-of-service vulnerability because it fails to handle malicious PNG files.

Successful exploits may allow remote attackers to cause denial-of-service conditions on computers running the affected library.

This issue affects 'libpng' 1.2.32; other versions may also be affected.


It is now suggested to update the package to 1.2.33rc02 ...


 Profile Send private message  
 
 Post subject: Re: [CVE-2008-3964]libpng 1.2.x<1.2.32beta01, Denial of service
PostPosted: Tue Dec 16, 2008 10:15 am 
Global Moderator
Global Moderator
User avatar

Joined: Sat Aug 05, 2006 9:38 am
Posts: 4604
libpng-1.2.33, is in the snapshot.


 Profile Send private message  
 
 Post subject: Re: [CVE-2008-3964]libpng 1.2.x<1.2.32beta01, Denial of service
PostPosted: Wed Dec 17, 2008 1:01 am 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
Thank you! \!D/


 Profile Send private message  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 5 posts ] 

All times are UTC


 Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
 
cron