Oval Definition:oval:org.mitre.oval:tst:30788
Comment:libpng is earlier than 2:1.2.2-25
Type:rpminfo_testNamespace:linux
Check_Existence:at_least_one_existsCheck:at least one
State Operator:AND
References
Object:oval:org.mitre.oval:obj:14194
Object:oval:org.mitre.oval:obj:952
State:oval:org.mitre.oval:ste:9381
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:10083
V
Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers.
2013-04-29
oval:org.mitre.oval:def:10203
V
The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null dereference.
2013-04-29
oval:org.mitre.oval:def:10938
V
Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.
2013-04-29
oval:org.mitre.oval:def:11284
V
Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.
2013-04-29
BACK