> Linux Reviews > News and headlines > 2004 News archive > August >

New libpng package closes buffer overflow and other security vulnerabilities

2004-08-05

The buffer overflow could in a worst case scenario be used to execute arbitrary code. Libpng is used by important applications like the Mozilla Suite.

US-Cert yesterday announced Technical Cyber Security Alert TA04-217A, "Several vulnerabilities exist in the libpng library, the most serious of which could allow a remote attacker to execute arbitrary code on an affected system."

The alert addresses four security issues:

SuSE Linux announced updated libpng packages yesterday, followed by Gentoo Linux and Trustix Linux who made patched versions of libpng available today.

Libpng 1.2.6rc1 is safe and is available from the libnpg sourceforce project page. Libpng 1.2.6 will be released sometime this month.


> Linux Reviews > News and headlines > 2004 News archive > August >
New libpng package closes buffer overflow and other security vulnerabilities