Package: libpng
Severity: important
Tags: security

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for libpng.

CVE-2007-5269[0]:
| Certain chunk handlers in libpng before 1.0.29 and 1.2.x before 1.2.21
| allow remote attackers to cause a denial of service (crash) via
| crafted (1) pCAL (png_handle_pCAL), (2) sCAL (png_handle_sCAL), (3)
| tEXt (png_push_read_tEXt), (4) iTXt (png_handle_iTXt), and (5) ztXT
| (png_handle_ztXt) chunking in PNG images, which trigger out-of-bounds
| read operations.

If you fix this vulnerability please also include the CVE id
in your changelog entry.

For further information:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5269

Kind regards
Nico

-- 
Nico Golde - http://ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgp3Xd5XhOYTx.pgp
Description: PGP signature

Reply via email to