[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2072-1 libpng -- several

ID: oval:org.secpod.oval:def:600073Date: (C)2011-01-28   (M)2024-02-19
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in libpng, a library for reading and writing PNG files. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-1205 It was discovered a buffer overflow in libpng which allows remote attackers to execute arbitrary code via a PNG image that triggers an additional data row. CVE-2010-2249 It was discovered a memory leak in libpng which allows remote attackers to cause a denial of service via a PNG image containing malformed Physical Scale chunks For the stable distribution , these problems have been fixed in version 1.2.27-2+lenny4. For the testing and unstable distribution, these problems have been fixed in version 1.2.44-1 We recommend that you upgrade your libpng package.

Platform:
Debian 5.0
Product:
libpng
Reference:
DSA-2072-1
CVE-2010-1205
CVE-2010-2249
CVE    2
CVE-2010-2249
CVE-2010-1205
CPE    1
cpe:/o:debian:debian_linux:5.x

© SecPod Technologies