Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51239
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2002:152
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory RHSA-2002:152.

Updated libpng packages are available that fix a buffer overflow vulnerability.

The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files. PNG
is a bit-mapped graphics format similar to the GIF format.

Versions of libpng prior to 1.0.14 contain a buffer overflow in the
progressive reader when the PNG datastream contains more IDAT data than
indicated by the IHDR chunk. Such deliberately malformed datastreams would
crash applications linked to libpng such as Mozilla that use the
progressive reading feature.

Packages within Red Hat Linux Advanced Server , such as Mozilla, make use
of the shared libpng library, therefore all users are advised to upgrade to
the errata packages which contain libpng 1.0.14. Libpng 1.0.14 is not
vulnerable to this issue and contains fixes for other bugs including a
number of memory leaks.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2002-152.html

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2002-0660
Debian Security Information: DSA-140 (Google Search)
https://www.debian.org/security/2002/dsa-140
RedHat Security Advisories: RHSA-2002:151
http://rhn.redhat.com/errata/RHSA-2002-151.html
RedHat Security Advisories: RHSA-2002:152
http://rhn.redhat.com/errata/RHSA-2002-152.html
Common Vulnerability Exposure (CVE) ID: CVE-2002-0728
Conectiva Linux advisory: CLA-2002:512
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000512
http://www.debian.org/security/2002/dsa-140
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-049.php
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.