exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Open Source CERT Security Advisory 2008.3

Open Source CERT Security Advisory 2008.3
Posted Apr 14, 2008
Authored by Tavis Ormandy, Open Source CERT | Site ocert.org

Applications using libpng that install unknown chunk handlers, or copy unknown chunks, may be vulnerable to a security issue which may result in incorrect output, information leaks, crashes, or arbitrary code execution. The libpng project indicates libpng-1.0.6 through 1.0.32, libpng-1.2.0 through 1.2.26, and libpng-1.4.0beta01 through libpng-1.4.0beta19 built with PNG_READ_UNKNOWN_CHUNKS_SUPPORTED or PNG_READ_USER_CHUNKS_SUPPORTED (default configuration) are affected.

tags | advisory, arbitrary, code execution
advisories | CVE-2008-1382
SHA-256 | d9f18b2e078424f7549cd605507ce814b470dc6ff811315a92fb7070cf843236

Open Source CERT Security Advisory 2008.3

Change Mirror Download

2008/04/12 #2008-003 libpng zero-length chunks incorrect handling

Description:

Applications using libpng that install unknown chunk handlers, or copy
unknown chunks, may be vulnerable to a security issue which may result in
incorrect output, information leaks, crashes, or arbitrary code execution.

The issue involves libpng incorrectly handling zero length chunks which
results in uninitialized memory affecting the control flow of the
application.

Affected version:

The libpng project indicates libpng-1.0.6 through 1.0.32, libpng-1.2.0
through 1.2.26, and libpng-1.4.0beta01 through libpng-1.4.0beta19 built with
PNG_READ_UNKNOWN_CHUNKS_SUPPORTED or PNG_READ_USER_CHUNKS_SUPPORTED (default
configuration) are affected.

Fixed version:

libpng version 1.2.27 and 1.0.33 are in beta and will be released on or about
April 26, 2008 according to libpng maintainer

libpng-1.2.27beta01

Credit: Tavis Ormandy, oCERT Team | Google Security Team

CVE: CVE-2008-1382

Timeline:

2008-04-05: contacted libpng maintainers
2008-04-05: vendor confirms
2008-04-05: verification of vendor suggested patch
2008-04-12: libpng-1.2.27beta01 released
2008-04-12: libpng project advisory released
2008-04-12: advisory release

References:
http://libpng.sourceforge.net/Advisory-1.2.26.txt

Links:
http://www.libpng.org/pub/png/libpng.html

Permalink:
http://www.ocert.org/advisories/ocert-2008-003.html

--
Andrea Barisani | Founder & Project Coordinator
oCERT | Open Source Computer Emergency Response Team

<lcars@ocert.org> http://www.ocert.org
0x864C9B9E 0A76 074A 02CD E989 CE7F AC3F DA47 578E 864C 9B9E
"Pluralitas non est ponenda sine necessitate"
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close