Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 25 Feb 2009 17:19:26 +0100
From: Robert Buchholz <rbu@...too.org>
To: oss-security@...ts.openwall.com
Cc: Marcus Meissner <meissner@...e.de>
Subject: Re: CVE request: optipng security release

On Tuesday 24 February 2009, Marcus Meissner wrote:
> Hi,
>
> According to http://optipng.sourceforge.net/
>
> optipng released OptiPNG 0.6.2 fixing
> "All current OptiPNG versions are known to be vulnerable to memory
> reallocation attacks, due to a bug in the GIF image reader.

Note that this is not fixed in 0.6.2, but there is a patch to apply on 
top of 0.6.2.
0.6.2 was the release fixing CVE-2008-5101 (bmp issue).


Robert

[ CONTENT OF TYPE application/pgp-signature SKIPPED ]

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ