Bug 690200 (CVE-2006-7244, CVE-2009-5063)
Summary: | libpng10, libpng: Memory leak by write of iCCP chunk with negative embedded profile length (CVE-2006-7244, CVE-2009-5063) | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED NOTABUG | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | bressers, paul, tgl |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2011-04-07 20:06:56 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Jan Lieskovsky
2011-03-23 15:03:25 UTC
As noted in [1]: i), the bug was introduced in 1.2.13beta1: http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commitdiff;h=0ff85c6923d2c4fca4ac0bad28e387e3b1777d7a#patch19 ii), and finally fixed in 1.2.39beta5: http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commitdiff;h=9e88fcd58c8ce7f2183bc2045e5180cba0043f09#patch19 This issue did NOT affect the version of the libpng10 package, as shipped with Red Hat Enterprise Linux 4. This issue did NOT affect the versions of the libpng package, as shipped with Red Hat Enterprise Linux 4, 5, and 6. -- This issue did NOT affect the versions of the libpng10 package, as shipped with Fedora release of 13 and 14 and as present within EPEL-6 repository, as they already contain a fix for the issue. This issue did NOT affect the versions of the libpng package, as shipped with Fedora release of 13 and 14, as they already include the fix for the issue. For completeness, it's also worth noting that there is no EPEL-5 package of libpng10, nor was it shipped with Red Hat Enterprise Linux 5. In the current RHEL4 and RHEL5 packages, the embedded profile length is simply ignored. While that might be a bug in itself, there's no security impact AFAICS. Statement: These flaws do not affect any version of libpng shipped with Red Hat Enterprise Linux. |