[<prev] [next>] [day] [month] [year] [list]
Message-ID: <45745a08.oQikds2tE45+5mJM%announce-noreply@rpath.com>
Date: Mon, 04 Dec 2006 12:25:28 -0500
From: rPath Update Announcements <announce-noreply@...th.com>
To: security-announce@...ts.rpath.com, update-announce@...ts.rpath.com
Cc: lwn@....net, full-disclosure@...ts.grok.org.uk, bugtraq@...urityfocus.com
Subject: rPSA-2006-0211-2 doxygen libpng
rPath Security Advisory: 2006-0211-2
Published: 2006-11-15
Updated:
2006-12-04 added doxygen to advisory
Products: rPath Linux 1
Rating: Minor
Exposure Level Classification:
Indirect Deterministic Denial of Service
Updated Versions:
libpng=/conary.rpath.com@rpl:devel//1/1.2.13-0.1-1
doxygen=/conary.rpath.com@rpl:devel//1/1.4.3-6.2-1
References:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5793
https://issues.rpath.com/browse/RPL-790
https://issues.rpath.com/browse/RPL-824
Description:
Previous versions of the libpng package are vulnerable to a denial
of service attack when an application that uses libpng attempts to
decode certain malformed PNG files.
4 December 2006 Update: previous versions of the doxygen package
include internal copies of the libpng and zlib libraries, and the
libpng library contained multiple vulnerabilities. The doxygen
package has been modified to use system shared libraries for
libpng and zlib, resolving these vulnerabilities for doxygen.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists