Oval Definition:oval:org.mitre.oval:def:10614
Revision Date:2013-04-29Version:13
Title:Certain chunk handlers in libpng before 1.0.29 and 1.2.x before 1.2.21 allow remote attackers to cause a denial of service (crash) via crafted (1) pCAL (png_handle_pCAL), (2) sCAL (png_handle_sCAL), (3) tEXt (png_push_read_tEXt), (4) iTXt (png_handle_iTXt), and (5) ztXT (png_handle_ztXt) chunking in PNG images, which trigger out-of-bounds read operations.
Description:Certain chunk handlers in libpng before 1.0.29 and 1.2.x before 1.2.21 allow remote attackers to cause a denial of service (crash) via crafted (1) pCAL (png_handle_pCAL), (2) sCAL (png_handle_sCAL), (3) tEXt (png_push_read_tEXt), (4) iTXt (png_handle_iTXt), and (5) ztXT (png_handle_ztXt) chunking in PNG images, which trigger out-of-bounds read operations.
Family:unixClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2007-5269
Platform(s):CentOS Linux 3
CentOS Linux 4
CentOS Linux 5
Oracle Linux 4
Oracle Linux 5
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Product(s):
Definition Synopsis
  • OS Section: RHEL3, CentOS3
  • RHEL3 or CentOS3
  • The operating system installed on the system is Red Hat Enterprise Linux 3
  • OR CentOS Linux 3.x
  • AND Configuration section
  • libpng10-devel is earlier than 0:1.0.13-18
  • OR libpng-devel is earlier than 2:1.2.2-28
  • OR libpng is earlier than 2:1.2.2-28
  • OR libpng10 is earlier than 0:1.0.13-18
  • OR OS Section: RHEL4, CentOS4, Oracle Linux 4
  • RHEL4, CentOS4 or Oracle Linux 4
  • The operating system installed on the system is Red Hat Enterprise Linux 4
  • OR CentOS Linux 4.x
  • OR Oracle Linux 4.x
  • AND Configuration section
  • libpng10-devel is earlier than 0:1.0.16-3.el4_5.1
  • OR libpng-devel is earlier than 2:1.2.7-3.el4_5.1
  • OR libpng is earlier than 2:1.2.7-3.el4_5.1
  • OR libpng10 is earlier than 0:1.0.16-3.el4_5.1
  • OR OS Section: RHEL5, CentOS5, Oracle Linux 5
  • RHEL5, CentOS5 or Oracle Linux 5
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • OR The operating system installed on the system is CentOS Linux 5.x
  • OR Oracle Linux 5.x
  • AND Configuration section
  • libpng-devel is earlier than 2:1.2.10-7.1.el5_0.1
  • OR libpng is earlier than 2:1.2.10-7.1.el5_0.1
  • BACK