MGASA-2021-0210 - Updated pngcheck packages fix a security vulnerability

Publication date: 12 May 2021
URL: https://advisories.mageia.org/MGASA-2021-0210.html
Type: security
Affected Mageia releases: 7, 8

This update fixes a divide-by-zero crash bug (and probable vulnerability) in
interlaced images with extra compressed data beyond the nominal end of the
image data. (found by "chiba of topsec alpha lab") (rhbz#1949800).

References:
- https://bugs.mageia.org/show_bug.cgi?id=28879
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DGE643ALPDU76YXVRUPIB5FNWLYX3PXF/

SRPMS:
- 8/core/pngcheck-3.0.3-1.mga8
- 7/core/pngcheck-3.0.3-1.mga7

Mageia 2021-0210: pngcheck security update

This update fixes a divide-by-zero crash bug (and probable vulnerability) in interlaced images with extra compressed data beyond the nominal end of the image data

Summary

This update fixes a divide-by-zero crash bug (and probable vulnerability) in interlaced images with extra compressed data beyond the nominal end of the image data. (found by "chiba of topsec alpha lab") (rhbz#1949800). References:

References

- https://bugs.mageia.org/show_bug.cgi?id=28879

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DGE643ALPDU76YXVRUPIB5FNWLYX3PXF/

Resolution

MGASA-2021-0210 - Updated pngcheck packages fix a security vulnerability

SRPMS

- 8/core/pngcheck-3.0.3-1.mga8

- 7/core/pngcheck-3.0.3-1.mga7

Severity
Publication date: 12 May 2021
URL: https://advisories.mageia.org/MGASA-2021-0210.html
Type: security

Related News