libpng vulnerability

Forum thread started by Kev on Thu, 2004-08-05 13:06

Comments

libpng vulnerability

Yes. libpng is used in the app_server and the translation kit.

libpng vulnerability

But, I mean, is the vulnerability in our version? They said Windows versions of libpng may not be affected. I was just wondering how different our version was from the standard, or if it was different at all.

Sorry, I really don't know what I'm talking about. :)

Kev

libpng vulnerability

the BeOS version is exactly the same as the other UNIX versions I beleive.

Re: libpng vulnerability

Kev wrote:
Does this apply to us?

http://www.us-cert.gov/cas/techalerts/TA04-217A.html

Kev

It appears that the solution as suggested by CERT is to upgrade libpng code to version 1.2.6rc1 which resolves the issues... so I would guess it's just a matter of upgrading/re-porting the code in CVS ?