Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Mandrake Local Security Checks >> MDKSA-2006:209: libpng


Vulnerability Assessment Details

MDKSA-2006:209: libpng

Vulnerability Assessment Summary
Check for the version of the libpng package

Detailed Explanation for this Vulnerability Assessment

The remote host is missing the patch for the advisory MDKSA-2006:209 (libpng).

Buffer overflow in the png_decompress_chunk function in pngrutil.c in
libpng before 1.2.12 permits context-dependent attackers to cause a
denial of service and possibly execute arbitrary code via unspecified
vectors related to 'chunk error processing,' possibly involving the
'chunk_name'. (CVE-2006-3334)
It is questionable whether this issue is actually exploitable, but the
patch to correct the issue has been included in versions < 1.2.12.
Tavis Ormandy, of the Gentoo Linux Security Auditing Team, discovered a
typo in png_set_sPLT() that may cause an application using libpng to
read out of bounds, resulting in a crash. (CVE-2006-5793)
Packages have been patched to correct these issues.

Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:209
Network Security Threat Level: High

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2007 Tenable Network Security

Cables, Connectors


Lot of 5 - Intel Xeon E5-2650v4 2.20GHz 12-Core 30M Server CPU 105W SR2N3 picture

Lot of 5 - Intel Xeon E5-2650v4 2.20GHz 12-Core 30M Server CPU 105W SR2N3

$69.99



Intel Core i5-8500 (8th Gen) 3.00GHz 6-Core Desktop CPU 9MB LGA1151 SR3XE picture

Intel Core i5-8500 (8th Gen) 3.00GHz 6-Core Desktop CPU 9MB LGA1151 SR3XE

$50.00



Intel Core i7-4790 3.60GHz Quad Core CPU Processor SR1QF LGA 1150 Socket picture

Intel Core i7-4790 3.60GHz Quad Core CPU Processor SR1QF LGA 1150 Socket

$32.99



Intel Core i9-12900KF - 12th Gen Alder Lake 16-Core (8P+8E) 3.2GHz LGA CPU picture

Intel Core i9-12900KF - 12th Gen Alder Lake 16-Core (8P+8E) 3.2GHz LGA CPU

$262.99



intel i7-960 3.06 ghz lga1366 processor picture

intel i7-960 3.06 ghz lga1366 processor

$14.00



Intel Xeon E5-2697A V4 2.6GHz CPU Processor 16-Core Socket LGA2011 SR2K1 picture

Intel Xeon E5-2697A V4 2.6GHz CPU Processor 16-Core Socket LGA2011 SR2K1

$39.99



Intel Core i9-14900KF Unlocked Desktop Processor picture

Intel Core i9-14900KF Unlocked Desktop Processor

$588.71



Intel Core i7-8700 Processor (3.2 GHz, 6 Cores, LGA 1151) - SR3QS picture

Intel Core i7-8700 Processor (3.2 GHz, 6 Cores, LGA 1151) - SR3QS

$98.00



Intel Core i7-7700 3.60GHz Quad-Core CPU picture

Intel Core i7-7700 3.60GHz Quad-Core CPU

$41.57



Intel Core i7-3770 3.40GHz 8MB Quad Core Socket LGA1155 CPU Processor SR0PK picture

Intel Core i7-3770 3.40GHz 8MB Quad Core Socket LGA1155 CPU Processor SR0PK

$35.00



Discussions

No Discussions have been posted on this vulnerability.