OpenPKG Security Advisory
OpenPKG-SA-2004.030
Publisher Name: OpenPKG GmbH
Publisher Home: http://openpkg.com/
Advisory Id (public): OpenPKG-SA-2004.030
Advisory Type: OpenPKG Security Advisory (SA)
Advisory Directory: http://openpkg.com/go/OpenPKG-SA
Advisory Document: http://openpkg.com/go/OpenPKG-SA-2004.030
Advisory Published: 2008-10-11 12:14 UTC
Issue Id (internal): OpenPKG-SI-20040706.01
Issue First Created: 2004-07-06
Issue Last Modified: 2006-11-28
Issue Revision: 06
Subject Name: libpng
Subject Summary: Portable Network Graphics (PNG) Image Format
Library
Subject Home: http://www.libpng.org/pub/png/
Subject Versions: * <= 1.2.5
Vulnerability Id: CVE-2002-1363
Vulnerability Scope: global (not OpenPKG specific)
Attack Feasibility: run-time
Attack Vector: local system
Attack Impact: denial of service
Description:
In a previous OpenPKG security advisory [0], a buffer overflow
vulnerability was addressed in the Portable Network Graphics (PNG)
library libpng [1] in connection with 16-bit samples. The starting
offsets for the loops are calculated incorrectly which may cause
a buffer overrun beyond the beginning of the row buffer.
References:
[0] http://www.openpkg.org/security/OpenPKG-SA-2003.001-png.html
[1] http://www.libpng.org/pub/png/
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1363
[3] http://www.openpkg.org/tutorial.html#regular-source
[4] http://www.openpkg.org/tutorial.html#regular-binary
[5] ftp://ftp.openpkg.org/release/1.3/UPD/png-1.2.5-1.3.2.src.rpm
[6] ftp://ftp.openpkg.org/release/2.0/UPD/png-1.2.5-2.0.2.src.rpm
[7] ftp://ftp.openpkg.org/release/1.3/UPD/
[8] ftp://ftp.openpkg.org/release/2.0/UPD/
[9] http://www.openpkg.org/security.html#signature
Primary Package Name: png
Primary Package Home: http://openpkg.org/go/package/png
Affected Distribution: Affected Branch: Affected Package:
OpenPKG Community 1.3-SOLID doxygen-1.3.3-1.3.1
OpenPKG Community 1.3-SOLID ghostscript-8.10-1.3.1
OpenPKG Community 1.3-SOLID pdflib-5.0.1-1.3.1
OpenPKG Community 1.3-SOLID perl-tk-1.3.0-1.3.1
OpenPKG Community 1.3-SOLID png-1.2.5-1.3.1
OpenPKG Community 1.3-SOLID rrdtool-1.0.45-1.3.1
OpenPKG Community 1.3-SOLID tetex-2.0.2-1.3.1
OpenPKG Community 2.0-SOLID doxygen-1.3.6-2.0.1
OpenPKG Community 2.0-SOLID ghostscript-8.13-2.0.1
OpenPKG Community 2.0-SOLID pdflib-5.0.3-2.0.1
OpenPKG Community 2.0-SOLID perl-tk-5.8.3-2.0.1
OpenPKG Community 2.0-SOLID png-1.2.5-2.0.1
OpenPKG Community 2.0-SOLID qt-3.2.3-2.0.1
OpenPKG Community 2.0-SOLID rrdtool-1.0.46-2.0.1
OpenPKG Community 2.0-SOLID tetex-2.0.2-2.0.1
OpenPKG Community CURRENT doxygen-1.3.7-20040507
OpenPKG Community CURRENT ghostscript-8.14-20040604
OpenPKG Community CURRENT png-1.2.5-20040527
Corrected Distribution: Corrected Branch: Corrected Package:
OpenPKG Community 1.3-SOLID doxygen-1.3.3-1.3.2
OpenPKG Community 1.3-SOLID ghostscript-8.10-1.3.2
OpenPKG Community 1.3-SOLID pdflib-5.0.1-1.3.2
OpenPKG Community 1.3-SOLID perl-tk-1.3.0-1.3.2
OpenPKG Community 1.3-SOLID png-1.2.5-1.3.2
OpenPKG Community 1.3-SOLID rrdtool-1.0.45-1.3.2
OpenPKG Community 1.3-SOLID tetex-2.0.2-1.3.2
OpenPKG Community 2.0-SOLID doxygen-1.3.6-2.0.2
OpenPKG Community 2.0-SOLID ghostscript-8.13-2.0.2
OpenPKG Community 2.0-SOLID pdflib-5.0.3-2.0.2
OpenPKG Community 2.0-SOLID perl-tk-5.8.3-2.0.2
OpenPKG Community 2.0-SOLID png-1.2.5-2.0.2
OpenPKG Community 2.0-SOLID qt-3.2.3-2.0.2
OpenPKG Community 2.0-SOLID rrdtool-1.0.46-2.0.2
OpenPKG Community 2.0-SOLID tetex-2.0.2-2.0.2
OpenPKG Community CURRENT doxygen-1.3.7-20040630
OpenPKG Community CURRENT ghostscript-8.14-20040630
OpenPKG Community CURRENT png-1.2.5-20040629