CERT-In Vulnerability Note
CIVN-2006-0119
LibPNG Graphics Library PNG_SET_SPLT Remote Denial of Service Vulnerability
Original Issue Date:November 21, 2006
Severity Rating: HIGH
Systems Affected
libPNG version prior to 1.2.12
Overview
A vulnerability has been reported in LibPNG package which could be exploited by remote attackers cause denial of service attack.
Description
A vulnerability has been reported in LibPNG package due to an error in the "png_set_sPLT " [pngset.c] function while processing a malformed PNG file.
This vulnerability could be exploited by a remote attacker to crash the vulnerable application.
Solution
Upgrade to version 1.2.13 or 1.4.0beta14
http://sourceforge.net/projects/libpng/
Vendor Information
LibPNG
http://www.libpng.org/pub/png/
References
Secunia
http://secunia.com/advisories/22889
FrSI RT
http://www.frsirt.com/english/advisories/2006/4521
Security Tracker
http://securitytracker.com/alerts/2006/Nov/1017244.html
Security Focus
http://www.securityfocus.com/bid/21078
CVE Name
CVE-2006-5793
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|