Oval Definition:oval:com.redhat.rhsa:def:20050793
Revision Date:2005-10-18Version:502
Title:RHSA-2005:793: netpbm security update (Moderate)
Description:The netpbm package contains a library of functions that support programs for handling various graphics file formats, including .pbm (portable bitmaps), .pgm (portable graymaps), .pnm (portable anymaps), .ppm (portable pixmaps) and others.

A bug was found in the way netpbm converts Portable Anymap (PNM) files into Portable Network Graphics (PNG). The usage of uninitialised variables in the pnmtopng code allows an attacker to change stack contents when converting to PNG files with pnmtopng using the '-trans' option. This may allow an attacker to execute arbitrary code. The Common Vulnerabilities and Exposures project assigned the name CAN-2005-2978 to this issue.

All users of netpbm should upgrade to the updated packages, which contain a backported patch to resolve this issue.
Family:unixClass:patch
Status:Reference(s):CVE-2005-2978
RHSA-2005:793-01
Platform(s):Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 4 is installed
  • AND Package Information
  • netpbm is earlier than 0:10.25-2.EL4.2
  • AND netpbm is signed with Red Hat master key
  • OR
  • netpbm-devel is earlier than 0:10.25-2.EL4.2
  • AND netpbm-devel is signed with Red Hat master key
  • OR
  • netpbm-progs is earlier than 0:10.25-2.EL4.2
  • AND netpbm-progs is signed with Red Hat master key
  • BACK