CVE Reference: CVE-2002-1363

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2002-1363

Description:
Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers.

CVE Status:
Entry

References:

XF
  http://xforce.iss.net/xforce/xfdb/10925

SUSE
  http://www.novell.com/linux/security/advisories/2003_004_libpng.html

REDHAT
  http://www.redhat.com/support/errata/RHSA-2003-006.html
  http://www.redhat.com/support/errata/RHSA-2003-007.html
  http://www.redhat.com/support/errata/RHSA-2003-119.html
  http://www.redhat.com/support/errata/RHSA-2003-157.html
  http://www.redhat.com/support/errata/RHSA-2004-249.html
  http://www.redhat.com/support/errata/RHSA-2004-402.html

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3657

MANDRAKE
  http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:063
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:008

FEDORA

DEBIAN
  http://www.debian.org/security/2002/dsa-213

BID
  6431


Return to the previous page.