lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <45745a08.oQikds2tE45+5mJM%announce-noreply@rpath.com>
Date: Mon, 04 Dec 2006 12:25:28 -0500
From: rPath Update Announcements <announce-noreply@...th.com>
To: security-announce@...ts.rpath.com,
	update-announce@...ts.rpath.com
Cc: full-disclosure@...ts.grok.org.uk, bugtraq@...urityfocus.com,
	lwn@....net
Subject: rPSA-2006-0211-2 doxygen libpng

rPath Security Advisory: 2006-0211-2
Published: 2006-11-15
Updated:
    2006-12-04 added doxygen to advisory
Products: rPath Linux 1
Rating: Minor
Exposure Level Classification:
    Indirect Deterministic Denial of Service
Updated Versions:
    libpng=/conary.rpath.com@rpl:devel//1/1.2.13-0.1-1
    doxygen=/conary.rpath.com@rpl:devel//1/1.4.3-6.2-1

References:
    http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5793
    https://issues.rpath.com/browse/RPL-790
    https://issues.rpath.com/browse/RPL-824

Description:
    Previous versions of the libpng package are vulnerable to a denial
    of service attack when an application that uses libpng attempts to
    decode certain malformed PNG files.
    
    4 December 2006 Update: previous versions of the doxygen package
    include internal copies of the libpng and zlib libraries, and the
    libpng library contained multiple vulnerabilities.  The doxygen
    package has been modified to use system shared libraries for
    libpng and zlib, resolving these vulnerabilities for doxygen.

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ