CVE-2009-0040
Publication date 22 February 2009
Last updated 24 July 2024
Ubuntu priority
The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
firefox-3.0 | ||
firefox-3.5 | ||
iceape | ||
icedove | ||
libpng | ||
mozilla-thunderbird | ||
seamonkey | ||
thunderbird | ||
xulrunner | ||
xulrunner-1.9 | ||
xulrunner-1.9.1 | ||