Index: vuln.xml =================================================================== RCS file: /home/pcvs/ports/security/vuxml/vuln.xml,v retrieving revision 1.2130 diff -u -r1.2130 vuln.xml --- vuln.xml 23 Mar 2010 08:36:57 -0000 1.2130 +++ vuln.xml 24 Mar 2010 16:19:19 -0000 @@ -34,6 +34,32 @@ --> + + libpng -- decompression denial of service + + + png + 1.4.1 + + + + +

The PNG project reports a denial of service vulnerability:

+
+

Malformed PNG chunks can consume a large amount of CPU and wall-clock time and large amounts of memory, up to all memory available on a system.

+
+ +
+ + http://libpng.sourceforge.net/ADVISORY-1.4.1.html + CVE-2010-0205 + + + 2010-02-27 + 2010-03-24 + +
+ firefox -- WOFF heap corruption due to integer overflow