LibPNG不合法PNG越界访问拒绝服务漏洞

漏洞信息详情

LibPNG不合法PNG越界访问拒绝服务漏洞

漏洞简介

libpng是多种应用程序使用的解析PNG图象格式的库。
libpng不正确处理部分不合法PNG图象,远程攻击者可以利用这个漏洞对使用这库的应用程序进行拒绝服务攻击。
攻击者构建特殊的PNG文件,可引起连接到libpng库的应用程序打开时,由于越界访问而导致崩溃,产生拒绝服务。

漏洞公告

厂商补丁:
Debian
——

http://www.debian.org/security/2004/dsa-498

MandrakeSoft
————
MandrakeSoft已经为此发布了一个安全公告(MDKSA-2004:040)以及相应补丁:

MDKSA-2004:040:Updated libpng packages fix vulnerability

链接:http://www.linux-mandrake.com/en/security/2004/2004-040.php” target=”_blank”>
http://www.linux-mandrake.com/en/security/2004/2004-040.php

补丁下载:

Updated Packages:

Mandrakelinux 10.0:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/libpng3-1.2.5-10.2.100mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/libpng3-devel-1.2.5-10.2.100mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/libpng3-static-devel-1.2.5-10.2.100mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/SRPMS/libpng-1.2.5-10.2.100mdk.src.rpm

Corporate Server 2.1:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/libpng3-1.2.4-3.4.C21mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/libpng3-devel-1.2.4-3.4.C21mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/libpng3-static-devel-1.2.4-3.4.C21mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/SRPMS/libpng-1.2.4-3.4.C21mdk.src.rpm

Corporate Server 2.1/x86_64:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/x86_64/corporate/2.1/RPMS/libpng3-1.2.4-3.4.C21mdk.x86_64.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/x86_64/corporate/2.1/RPMS/libpng3-devel-1.2.4-3.4.C21mdk.x86_64.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/x86_64/corporate/2.1/RPMS/libpng3-static-devel-1.2.4-3.4.C21mdk.x86_64.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/x86_64/corporate/2.1/SRPMS/libpng-1.2.4-3.4.C21mdk.src.rpm

Mandrakelinux 9.1:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/RPMS/libpng3-1.2.5-2.2.91mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/RPMS/libpng3-devel-1.2.5-2.2.91mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/RPMS/libpng3-static-devel-1.2.5-2.2.91mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/SRPMS/libpng-1.2.5-2.2.91mdk.src.rpm

Mandrakelinux 9.1/PPC:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/RPMS/libpng3-1.2.5-2.2.91mdk.ppc.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/RPMS/libpng3-devel-1.2.5-2.2.91mdk.ppc.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/RPMS/libpng3-static-devel-1.2.5-2.2.91mdk.ppc.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/SRPMS/libpng-1.2.5-2.2.91mdk.src.rpm

Mandrakelinux 9.2:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.2/RPMS/libpng3-1.2.5-7.2.92mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.2/RPMS/libpng3-devel-1.2.5-7.2.92mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.2/RPMS/libpng3-static-devel-1.2.5-7.2.92mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.2/SRPMS/libpng-1.2.5-7.2.92mdk.src.rpm

Mandrakelinux 9.2/AMD64:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/amd64/9.2/RPMS/lib64png3-1.2.5-7.2.92mdk.amd64.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/amd64/9.2/RPMS/lib64png3-devel-1.2.5-7.2.92mdk.amd64.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/amd64/9.2/RPMS/lib64png3-static-devel-1.2.5-7.2.92mdk.amd64.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/amd64/9.2/SRPMS/libpng-1.2.5-7.2.92mdk.src.rpm

Multi Network Firewall 8.2:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/mnf8.2/RPMS/libpng3-1.2.4-3.4.M82mdk.i586.rpm


来源: BID
名称: 10244
链接:http://www.securityfocus.com/bid/10244

来源: REDHAT
名称: RHSA-2004:180
链接:http://www.redhat.com/support/errata/RHSA-2004-180.html

来源: XF
名称: libpng-png-dos(16022)
链接:http://xforce.iss.net/xforce/xfdb/16022

来源: REDHAT
名称: RHSA-2004:181
链接:http://www.redhat.com/support/errata/RHSA-2004-181.html

来源: DEBIAN
名称: DSA-498
链接:http://www.debian.org/security/2004/dsa-498

来源: OVAL
名称: oval:org.mitre.oval:def:11710
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11710

来源: FEDORA
名称: FEDORA-2004-106
链接:http://marc.theaimsgroup.com/?l=fedora-announce-list&m=108451353608968&w=2

来源: FEDORA
名称: FEDORA-2004-105
链接:http://marc.theaimsgroup.com/?l=fedora-announce-list&m=108451350029261&w=2

来源: TRUSTIX
名称: 2004-0025
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108335030208523&w=2

来源: BUGTRAQ
名称: 20040429 [OpenPKG-SA-2004.017] OpenPKG Security Advisory (png)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108334922320309&w=2

来源: APPLE
名称: APPLE-SA-2004-09-09
链接:http://lists.apple.com/mhonarc/security-announce/msg00056.html

来源: MANDRIVA
名称: MDKSA-2006:213
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:213

来源: MANDRIVA
名称: MDKSA-2006:212
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:212

来源: MANDRAKE
名称: MDKSA-2004:040
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2004:040

来源: SECUNIA
名称: 22958
链接:http://secunia.com/advisories/22958

来源: SECUNIA
名称: 22957
链接:http://secunia.com/advisories/22957

来源: US Government Resource: oval:org.mitre.oval:def:971
名称: oval:org.mitre.oval:def:971
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:971

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享