Submitted by KeesCook on Tue, 2007-06-12 00:43.
usn
Referenced CVEs:
CVE-2007-2445
Description:
===========================================================
Ubuntu Security Notice USN-472-1 June 11, 2007
libpng vulnerability
CVE-2007-2445
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libpng12-0 1.2.8rel-5ubuntu0.2
Ubuntu 6.10:
libpng12-0 1.2.8rel-5.1ubuntu0.2
Ubuntu 7.04:
libpng12-0 1.2.15~beta5-1ubuntu1
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Details follow:
It was discovered that libpng did not correctly handle corrupted CRC
in grayscale PNG images. By tricking a user into opening a specially
crafted PNG, a remote attacker could cause the application using libpng
to crash, resulting in a denial of service.


