~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2008-5907

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2008-5907
2
 
PublicDate: 2009-01-15
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5907
5
 
 http://libpng.sourceforge.net/index.html
6
 
 https://usn.ubuntu.com/usn/usn-730-1
7
 
Description:
8
 
 The png_check_keyword function in pngwutil.c in libpng before 1.0.42, and
9
 
 1.2.x before 1.2.34, might allow context-dependent attackers to set the
10
 
 value of an arbitrary memory location to zero via vectors involving
11
 
 creation of crafted PNG files with keywords, related to an implicit cast of
12
 
 the '\0' character constant to a NULL pointer.  NOTE: some sources
13
 
 incorrectly report this as a double free vulnerability.
14
 
Ubuntu-Description:
15
 
Notes:
16
 
 mdeslaur> This may not be a security issue, as it seems it's when writing png
17
 
 mdeslaur> see: http://openwall.com/lists/oss-security/2009/01/09/1
18
 
Bugs:
19
 
 https://bugs.launchpad.net/bugs/324258
20
 
Priority: low
21
 
Discovered-by:
22
 
Assigned-to: jdstrand
23
 
 
24
 
Patches_libpng:
25
 
upstream_libpng: released (1.2.35-1)
26
 
dapper_libpng: released (1.2.8rel-5ubuntu0.4)
27
 
gutsy_libpng: released (1.2.15~beta5-2ubuntu0.2)
28
 
hardy_libpng: released (1.2.15~beta5-3ubuntu0.1)
29
 
intrepid_libpng: released (1.2.27-1ubuntu0.1)
30
 
devel_libpng: released (1.2.27-2ubuntu2)