USN-1-1: PNG library vulnerabilities

23 October 2004

PNG library vulnerabilities

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 4.10

Software Description

Details

Several integer overflow vulnerabilities were discovered in the PNG library. These vulnerabilities could be exploited by an attacker by providing a specially crafted PNG image which, when processed by the PNG library, could result in the execution of program code provided by the attacker.

The PNG library is used by a variety of software packages for different purposes, so the exact nature of the exposure will vary depending on the software involved.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 4.10
libpng10-0
libpng10-dev
libpng12-0
libpng12-dev

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

References