Settings

Theme

Libpng 1.6.51: Four buffer overflow vulnerabilities fixed

openwall.com

45 points by ledoge 24 days ago · 9 comments

Reader

ziotom78 24 days ago

It’s fantastic they were able to find these issues!

That four new CVEs (two high-severity!) were found in a mature and well-tested library like png reminds me how non-trivial and unforgiving software engineering can be.

Security flaws are often just waiting behind the corner: this should be humbling lesson for all of us.

kevincox 24 days ago

> All vulnerabilities require user interaction (processing a malicious PNG file)

What world is the author living in where PNGs aren't very frequently read and written with no user interaction. The web obviously displays PNGs with no prompt, sites can generate PNGs with canvas trivially and with no explicit permission. PNGs are also often displayed in notifications and may come from untrustworthy sources.

This feels like an irresponsible downplay of the severity.

applied_heat 24 days ago

Affects back to version 1.6.0 released Feb 14, 2013

lousken 24 days ago

rust rewrite when?

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection