Bug 240398 - CVE-2007-2445: libpng10 DoS
CVE-2007-2445: libpng10 DoS
Status: CLOSED ERRATA
Product: Fedora
Classification: Fedora
Component: libpng10 (Show other bugs)
6
All Linux
medium Severity medium
: ---
: ---
Assigned To: Paul Howarth
Fedora Extras Quality Assurance
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2007-05-17 04:00 EDT by Ville Skyttä
Modified: 2007-11-30 17:12 EST (History)
1 user (show)

See Also:
Fixed In Version: 1.0.26-1.fc6
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2007-06-01 06:12:30 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Ville Skyttä 2007-05-17 04:00:09 EDT
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2445

"The png_handle_tRNS function in pngrutil.c in libpng before 1.0.25 and 1.2.x
before 1.2.17 allows remote attackers to cause a denial of service (application
crash) via a grayscale PNG image with a bad tRNS chunk CRC value."
Comment 1 Paul Howarth 2007-06-01 06:12:30 EDT
libpng10-1.0.26-1.fc6 has been released for Fedora Extras 6, which should
resolve this problem.

There is also a release libpng10-1.0.26-1.fc7.1 in Fedora 7 updates and
libpng10-1.0.26-1.fc8 for development.

Note You need to log in before you can comment on or make changes to this bug.