Saturday, October 9, 2010

Libpng: Multiple vulnerabilities

Users of Libpng please be advised of a Multiple vulnerabilities that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
GLSA 201010-01: [GLSA 201010-01] Libpng: Multiple vulnerabilities
Description

===========



Multiple vulnerabilities were found in libpng:



* The png_decompress_chunk() function in pngrutil.c does not properly

handle certain type of compressed data (CVE-2010-0205)



* A buffer overflow in pngread.c when using progressive applications

(CVE-2010-1205)



* A memory leak in pngrutil.c when dealing with a certain type of

chunks (CVE-2010-2249)
Read more at www.criticalwatch.com
 

No comments:

Post a Comment