Wind River Support Network

HomeOther DownloadsSecurity Issue: libpng - bug in png_handle_tRNS - CVE-2007-2445
Optional Type: Patch

Security Issue: libpng - bug in png_handle_tRNS - CVE-2007-2445

Released: Apr 25, 2008     Updated: Apr 25, 2008

Description

The png_handle_tRNS function in pngrutil.c in libpng before 1.0.25 and 1.2.x before 1.2.17 allows remote attackers to cause a denial of service (application crash) via a grayscale PNG image with a bad tRNS chunk CRC value.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2445 IDENTIFIER =


Product Version

Linux Platforms 1.x

Installation Notes

Installation Notes

  1. Unzip the patch under [install_dir]/updates

    2. Install the patch CD by entering the patch CD directory and run setup_linux.

    3. This is a source only patch so you will have to build the kernel

    4. Issue a make fs and make the kernel in a configured directory.

    5. Upload the kernel and rootfs into the target and boot it up.

Live chat
Online