Vulnerability Note VU#684664
libpng denial of service vulnerability
Overview
The libpng library contains a denial-of-service vulnerability.
Description
The libpng library can be used to allow other applications to render PNG images. The libpng library contains a denial-of-service vulnerability.
The reason is that png_ptr->num_trans is set to 1 and then there is an error return after checking the CRC, so the trans[ ] array is never allocated. Since png_ptr->num_trans is nonzero, libpng tries to use the array later. |
Impact
A remote, unauthenticated attacker may be able to create a denial-of-service condition. |
Solution
Upgrade |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Debian GNU/Linux | Affected | 08 May 2007 | 08 Jun 2007 |
| Gentoo Linux | Affected | 08 May 2007 | 08 Jun 2007 |
| libpng | Affected | 07 May 2007 | 16 May 2007 |
| Mandriva, Inc. | Affected | 08 May 2007 | 08 Jun 2007 |
| Red Hat, Inc. | Affected | 08 May 2007 | 18 May 2007 |
| Sun Microsystems, Inc. | Affected | 08 May 2007 | 22 Aug 2007 |
| SUSE Linux | Affected | 08 May 2007 | 13 Jul 2007 |
| Ubuntu | Affected | 08 May 2007 | 13 Jun 2007 |
| Apple Computer, Inc. | Unknown | 08 May 2007 | 08 May 2007 |
| Conectiva Inc. | Unknown | 08 May 2007 | 08 May 2007 |
| Cray Inc. | Unknown | 08 May 2007 | 08 May 2007 |
| EMC, Inc. (formerly Data General Corporation) | Unknown | 08 May 2007 | 08 May 2007 |
| Engarde Secure Linux | Unknown | 08 May 2007 | 08 May 2007 |
| F5 Networks, Inc. | Unknown | 08 May 2007 | 08 May 2007 |
| Fedora Project | Unknown | 08 May 2007 | 08 May 2007 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://sourceforge.net/project/showfiles.php?group_id=5624
- http://www.mirrorservice.org/sites/download.sourceforge.net/pub/sourceforge/l/li/libpng/libpng-1.2.17-ADVISORY.txt
- http://secunia.com/advisories/25292/
- http://secunia.com/advisories/25353/
- http://secunia.com/advisories/25742/
Credit
Thanks to the libpng team for information that was used in this report.
This document was written by Ryan Giobbi.
Other Information
- CVE IDs: CVE-2007-2445
- Date Public: 16 May 2007
- Date First Published: 16 May 2007
- Date Last Updated: 22 Aug 2007
- Severity Metric: 3.86
- Document Revision: 21
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.