oss-sec mailing list archives

Re: CVE request (libpng)


From: "Steven M. Christey" <coley () linus mitre org>
Date: Tue, 9 Sep 2008 10:32:58 -0400 (EDT)


On Tue, 9 Sep 2008, [UTF-8] Pınar Yanarda�^_ wrote:

libpng 1.2.32beta01 fixes an off-by-one error within the
"png_push_read_zTXt()" function in pngread.c when processing malicious
PNG images with specially crafted zTXt chunks.

Use CVE-2008-3964, to be filled in later.

- Steve


Current thread: