Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 13 Jul 2011 10:16:36 +0530
From: Huzaifa Sidhpurwala <>
Subject: Security issues fixed in libpng 1.5.4


There are three security issues which are fixed in libpng 1.5.4 [1].
The following CVE ids are assigned for those issues:

1. buffer overwrite in png_rgb_to_gray
CVE: CVE-2011-2690

2. Crash in png_default_error due to use of NULL Pointer
CVE: CVE-2011-2691

3. Memory corruption when handling empty sCAL chunks
CVE: CVE-2011-2692



Huzaifa Sidhpurwala / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.