Novell Home

CVE-2009-0749

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

CVE-2009-0749 at MITRE

Details

Use-after-free vulnerability in the GIFReadNextExtension function in lib/pngxtern/gif/gifread.c in OptiPNG 0.6.2 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a crafted GIF image that causes the realloc function to return a new pointer, which triggers memory corruption when the old pointer is accessed.
Novell Bugzilla entry: 479067,505103

SUSE Security Advisories:

Product(s) Fixed package version(s) References
openSUSE 10.3
  • optipng >= 0.6.2-2.3
ZYPP Patch Nr: 6290
SAT Patch Nr: 972
openSUSE 11.0
  • optipng-debuginfo >= 0.6.2-2.4
  • optipng-debugsource >= 0.6.2-2.4
ZYPP Patch Nr: 6290
SAT Patch Nr: 972
openSUSE 11.0
  • optipng >= 0.6.2-2.4
ZYPP Patch Nr: 6290
SAT Patch Nr: 972
openSUSE 11.1
  • optipng-debuginfo >= 0.6.1-10.4.1
ZYPP Patch Nr: 6290
SAT Patch Nr: 972
openSUSE 11.1
  • optipng >= 0.6.1-10.4.1
ZYPP Patch Nr: 6290
SAT Patch Nr: 972
openSUSE 10.3
  • optipng >= 0.6.2-2.1
ZYPP Patch Nr: 6038
SAT Patch Nr: 572
openSUSE 11.0
  • optipng-debuginfo >= 0.6.2-2.2
  • optipng-debugsource >= 0.6.2-2.2
ZYPP Patch Nr: 6038
SAT Patch Nr: 572
openSUSE 11.0
  • optipng >= 0.6.2-2.2
ZYPP Patch Nr: 6038
SAT Patch Nr: 572
openSUSE 11.1
  • optipng-debuginfo >= 0.6.1-10.3.1
ZYPP Patch Nr: 6038
SAT Patch Nr: 572
openSUSE 11.1
  • optipng >= 0.6.1-10.3.1
ZYPP Patch Nr: 6038
SAT Patch Nr: 572

Novell® Making IT Work As One

© 2009 Novell, Inc. All Rights Reserved.