Cybertrion Systems

[3/5] Cairo PNG Image Processing Integer Overflow

November 30th, 2007 by
[3/5] Cairo PNG Image Processing Integer Overflow

:A vulnerability has been reported in Cairo, which potentially can be exploited by malicious people to compromise an application using the library.The vulnerability is caused due to an integer overflow error within the "read_png()" function in cairo-png.c. This can be exploited to cause a heap-based buffer overflow via a specially crafted PNG file.Successful exploitation may allow execution of arbitrary code.The vulnerability is reported in versions prior to 1.4.12.Solution:Update to version 1.4.12.Provided and/or discovered by:Red Hat credits Peter Valchev, Google Security Team.Original Advisory:Red Hat:https://bugzilla.redhat.com/show_bug.cgi?id=387431Cairo:http://cairographics.org/news/cairo-1.4.12/

Original post by nitish

[3/5] Cairo PNG Image Processing Integer Overflow

Related Articles:
  • [3/5] CUPS PNG Filter Integer Overflow Vulnerability
  • [3/5] Slackware update for cairo
  • [4/5] ACDSee Products Image and Archive Plug-ins Buffer Overflows
  • [3/5] libexif Integer Overflow and Denial of Service
  • [3/5] rPath update for cairo


  • Posted in Advisories - Exploits | | [3/5] Cairo PNG Image Processing Integer Overflow

    << [2/5] OpenSSL FIPS Object Module PRNG Security Issue | [4/5] VLC Media Player ActiveX Plugin and FLAC Vulnerabilities >>