Wind River Support Network

HomeOther DownloadsSecurity Advisory - libpng - CVE-2008-3964
Recommended Type: Patch

Security Advisory - libpng - CVE-2008-3964

Released: Mar 4, 2009     Updated: Mar 4, 2009

Description

Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the png_push_read_zTXt function in pngread.c, and possibly related to (2) pngtest.c.


Product Version

Linux Platforms 1.x

Downloads


Caveats

N/A


Installation Notes

Installation Notes

1. Unzip the patch under [install_dir]/updates
2. Install the patch CD by entering the patch CD directory and run setup_linux.
3. This is a source only patch so you will have to build the kernel
4. Issue a make fs and make the kernel in a configured directory.
5. Upload the kernel and rootfs into the target and boot it up.


Live chat
Online