Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Mon, 22 Dec 2014 17:16:53 -0600
From: endeavor <endeavor@...nbowsandpwnies.com>
To: oss-security@...ts.openwall.com
Subject: CVE Request: libpng 1.6.15 Heap Overflow

I am requesting a CVE for a heap-overflow in libpng 1.6.15. It's my
understanding that versions 1.6.9-1.6.15 are vulnerable, and according to
patch notes it looks like some revisions in the 1.5 branch may have been
affected as well. However, I've only tested 1.6.15 and can only speak for
it.

Link to announcement of new version:
http://sourceforge.net/p/png-mng/mailman/message/33173461/

Link to a description of the vulnerability:
http://tfpwn.com/files/libpng_heap_overflow_1.6.15.txt

Please let me know!

- Alex

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.