nem ide tartozik, de debian sidben aznap (aug. 6) bekerult a javitas:
libpng3 (1.2.5.0-7) unstable; urgency=high
* pngrtran.c: applied upstream patch 4 to fix incorrect calculation of
buffer offsets [CAN-2004-0768].
* png.h, pngpread.c, pngrutil.c: patch from Chris Evans
to fix several vulnerabilities (closes: #263500):
+ libpng fails to properly check length on PNG data [CAN-2004-0597].
+ libpng „png_handle_sBIT” does not perform proper checks to avoid stack
buffer overflow [CAN-2004-0597].
+ libpng „png_handle_iCCP” possible NULL-pointer crash
[CAN-2004-0598].
+ libpng „png_handle_sPLT” possible integer overflow
[CAN-2004-0599].
+ libpng „png_read_png” does not properly handle a PNG with excessive
height (integer overflow) [CAN-2004-0599].
+ libpng progressive reading integer overflow [CAN-2004-0599].
— Josselin Mouette Thu, 5 Aug 2004 12:37:32 +0200
legutóbbi hsz