[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 25 Feb 2009 17:19:26 +0100
From: Robert Buchholz <rbu@...too.org>
To: oss-security@...ts.openwall.com
Cc: Marcus Meissner <meissner@...e.de>
Subject: Re: CVE request: optipng security release
On Tuesday 24 February 2009, Marcus Meissner wrote:
> Hi,
>
> According to http://optipng.sourceforge.net/
>
> optipng released OptiPNG 0.6.2 fixing
> "All current OptiPNG versions are known to be vulnerable to memory
> reallocation attacks, due to a bug in the GIF image reader.
Note that this is not fixed in 0.6.2, but there is a patch to apply on
top of 0.6.2.
0.6.2 was the release fixing CVE-2008-5101 (bmp issue).
Robert
[ CONTENT OF TYPE application/pgp-signature SKIPPED ]
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ