ASafety - AntiSecurity Un projet qui vous tiendra @coeur...

Critical hole closed in PNG reference library

Questions, réponses, sujets divers, news et informations

Sujets en relation avec cet article

ASBot
 

Critical hole closed in PNG reference library

Message non lude x[@♥] » Mar 29 Juin 2010 06:43

Critical hole closed in PNG reference library

Image

Intéressant. Je n'ai pas encore vu l'ombre d'un exploit ou d'un code de test toutefois j'ai le souvenir encore fraichement gravé en mémoire de la dernière vulnérabilité de type RCE que le format PNG renfermait. A cette époque ça avait vraiment fait des ravages...

Updates 1.2.44 and 1.4.3 for the official open source reference library libpng have been released to close security holes. Libpng is used by developers to help display and process images saved in "Portable Network Graphics" (PNG) format. The developers' advisory says that the old versions contain two flaws, one of which can be exploited to inject and execute code. It appears that libpng allows an additional image line to be processed even if the stated image height is smaller and it is this error which allows attackers to write code into memory.

As numerous browsers use libpng to display images, specially crafted web pages could infect visitors' PCs with malicious code. However, the developers say in their advisory that a successful attack depends on how specific applications use libpng. The Mozilla Foundation discovered the flaw, but it is currently not known whether Firefox is among the affected applications. The second flaw involves a memory problem in connection with flawed physical scale values (sCAL chunks) that can potentially cause the application to crash.

The developers have also released an update for the free libtiff library. Version 3.9.4 fixes a buffer overflow that can be provoked when processing specially crafted SubjectDistance tags. This hole is said to allow the injection of arbitrary code. This update also fully closes various holes (integer overflows) that were already meant to be closed in version 3.9.3.


Src here!

:hat:
Temp...
Avatar de l’utilisateur
x[@♥]
 
Messages: 1115
Inscription: Lun 21 Sep 2009 15:21
Localisation: Sur la root

Retourner vers Discussions



Qui est en ligne

Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 1 invité

cron