MGASA-2014-0211

Source
https://advisories.mageia.org/MGASA-2014-0211.html
Import Source
https://advisories.mageia.org/MGASA-2014-0211.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0211
Upstream
Published
2014-05-10T19:36:04Z
Modified
2026-04-16T06:25:50Z
Summary
Updated libpng packages fix two security vulnerabilities
Details

Updated libpng12 packages fix security vulnerabilities:

An integer overflow leading to a heap-based buffer overflow was found in the png_set_sPLT() and png_set_text_2() API functions of libpng. An attacker could create a specially-crafted image file and render it with an application written to explicitly call png_set_sPLT() or png_set_text_2() function, could cause libpng to crash or execute arbitrary code with the permissions of the user running such an application (CVE-2013-7353).

An integer overflow leading to a heap-based buffer overflow was found in the png_set_unknown_chunks() API function of libpng. An attacker could create a specially-crafted image file and render it with an application written to explicitly call png_set_unknown_chunks() function, could cause libpng to crash or execute arbitrary code with the permissions of the user running such an application (CVE-2013-7354).

References
Credits

Affected packages

Mageia:4 / libpng12

Package

Name
libpng12
Purl
pkg:rpm/mageia/libpng12?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.2.50-4.2.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0211.json"