Release date:
Updated on: 2010-08-19
Affected Systems:
Ben Wyatt glpng 1.45
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2010-1519
Glpng is an OpenGL library used to load PNG images in an OpenGL structure.
Glpng of the glpng library. the pngLoadRawF () and pngLoadF () functions in the c file have the integer overflow vulnerability that can eventually cause heap overflow when processing PNG images, users are deceived to use applications linked to the library to open malicious graphics files, which can trigger these overflow, resulting in arbitrary code execution.
<* Source: Secunia
Link: http://secunia.com/secunia_research/2010-87/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Ben Wyatt
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.fifi.org/doc/libglpng-dev/glpng.html