Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2020-35511: pngcheck: Buffer overflow in pngcheck 2.4.0 via a crafted png file | ||
---|---|---|---|
Product: | [openSUSE] openSUSE Distribution | Reporter: | Hu <cathy.hu> |
Component: | Security | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P3 - Medium | CC: | abergmann |
Version: | Leap 15.4 | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/340566/ | ||
Whiteboard: | |||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Hu
2022-08-24 07:15:46 UTC
Affected: - openSUSE:Backports:SLE-15-SP3/pngcheck 2.3.0 Not Affected: - openSUSE:Backports:SLE-15-SP4/pngcheck 3.0.0 - openSUSE:Factory/pngcheck 3.0.3 * 20201113 BB: fixed buffer-overflow vulnerability discovered by "giantbranch * of NSFOCUS Security Team" * https://bugzilla.redhat.com/show_bug.cgi?id=1897485 * 20201128 BB: found and fixed four additional vulnerabilities (null-pointer * dereference and three buffer overruns) * 20201209 LP: fixed an off-by-one bug in check_magic() (Lucy Phipps) * 20201209 LL: converted two zlib-version warnings/errors to go to stderr * (Lemures Lemniscati, actually from 20180318; forwarded by LP) * 20201210 BB: fixed another buffer-overflow vulnerability discovered by * "giantbranch of NSFOCUS Security Team" * https://bugzilla.redhat.com/show_bug.cgi?id=1905775 * 20201212 GRR: removed -f ("force") option due to multiple security issues * 20201212 GRR: released version 3.0.0 * ---------------------- I propose to update the pngcheck in backports to 3.0.3. In B15sp4 for sure (see http://www.libpng.org/pub/png/apps/pngcheck.html) and preferably also in B15sp3, even if -f option removed in 3.0.0. Packages submitted for B15sp4,B15sp3/pngcheck. I believe all fixed. This is an autogenerated message for OBS integration: This bug (1202662) was mentioned in https://build.opensuse.org/request/show/999895 Backports:SLE-15-SP3 / pngcheck openSUSE-SU-2022:10142-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1202662 CVE References: CVE-2020-35511 JIRA References: Sources used: openSUSE Backports SLE-15-SP3 (src): pngcheck-3.0.3-bp153.3.3.1 Fixed and released. |