The Portable Network Graphics library (libpng) contains a remotely exploitable vulnerability that could cause affected applications to crash.
The Portable Network Graphics (PNG) image format is used as an alternative to other image formats such as the Graphics Interchange Format (GIF). The libpng reference library is available for application developers to support the PNG image format.
Under some circumstances, a null pointer may be dereferenced during a memory allocation in the png_handle_iCCP() function. As a result, a PNG file with particular characteristics could cause the affected application to crash. Similar errors are reported to exist in other locations within libpng.
An attacker could cause a vulnerable application to crash by supplying a specially crafted PNG image. Vulnerable applications that read images from network sources could be exploited remotely.
Apply a patch from the vendor
Apple Computer, Inc.
MontaVista Software, Inc.
Red Hat, Inc.
Sun Microsystems, Inc.
Trustix Secure Linux
Juniper Networks, Inc.
Berkeley Software Design, Inc.
Ingrian Networks, Inc.
Sequent Computer Systems, Inc.
Wind River Systems, Inc.
Thanks to Chris Evans for reporting this vulnerability.
This document was written by Chad Dougherty and Damon Morda.
|Date First Published:||2004-08-04|
|Date Last Updated:||2007-07-21 02:33 UTC|