(Sun Issues Fix) libpng Chunk Handling Bugs Let Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1022308 |
|
SecurityTracker URL: http://securitytracker.com/id/1022308
|
|
CVE Reference:
CVE-2007-5269
(Links to External Site)
|
Date: May 30 2009
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 1.2 prior to 1.2.21 and 1.0 prior to 1.0.29
|
Description:
A vulnerability was reported in libpng. A remote user can cause denial of service conditions.
A remote user can create a specially crafted image that, when loaded by the target application, will trigger an out-of-bounds read error in certain chunk handlers and cause the target application to crash.
The png_handle_pCAL(), png_handle_sCAL(), png_push_read_tEXt(), png_handle_iTXt(), and png_handle_ztXt() functions are affected.
George Cook and Jeff Phillips reported this vulnerability.
|
Impact:
A remote user can cause denial of service conditions.
|
Solution:
Sun has issued a fix for Solaris 10 and OpenSolaris.
SPARC Platform
* Solaris 10 with patch 137080-03 or later
* OpenSolaris based upon builds snv_113 or later
x86 Platform
* Solaris 10 with patch 137081-03 or later
* OpenSolaris based upon builds snv_113 or later
Note that for Solaris 10 the issues referred to as CVE-2007-5267,
CVE-2008-3964, CVE-2007-5266, CVE-2007-5268, CVE-2007-5269, and
CVE-2008-1382 are resolved in patches 137080-02 and 137081-02 and
later revisions.
Sun is working on a fix for Solaris 8 and 9.
The Sun advisory is available at:
http://sunsolve.sun.com/search/document.do?assetkey=1-66-259989-1
|
Vendor URL: libpng.sourceforge.net/ (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
UNIX (Solaris - SunOS)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Sat, 30 May 2009 10:23:34 -0400
Subject: http://sunsolve.sun.com/search/document.do?assetkey=1-66-259989-1
|
CVE-2007-5266
CVE-2007-5267
CVE-2007-5268
CVE-2007-5269
CVE-2008-1382
CVE-2008-3964
CVE-2009-0040
|
|