NetPBM PNMToPNG Buffer Overflow Vulnerability
BID:15128
Info
NetPBM PNMToPNG Buffer Overflow Vulnerability
| Bugtraq ID: | 15128 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-2978 CVE-2005-2978 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2005 12:00AM |
| Updated: | Mar 19 2015 09:12AM |
| Credit: | The original discoverer of this issue is currently unknown. It was disclosed in an Ubuntu advisory. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Turbolinux Turbolinux Workstation 8.0 Turbolinux Turbolinux Workstation 7.0 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Server 7.0 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux 10 F... TurboLinux Personal TurboLinux Multimedia Turbolinux Home Trustix Secure Linux 2.2 Trustix Secure Linux 2.1 Trustix Secure Enterprise Linux 2.0 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 7 SGI ProPack 3.0 SP6 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Professional 7.3 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Desktop 1.0 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux WS 2.1 IA64 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux ES 2.1 IA64 RedHat Enterprise Linux ES 2.1 RedHat Desktop 4.0 RedHat Desktop 3.0 RedHat Advanced Workstation for the Itanium Processor 2.1 IA64 RedHat Advanced Workstation for the Itanium Processor 2.1 Red Hat Fedora Core4 Red Hat Fedora Core3 Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux AS 2.1 IA64 Red Hat Enterprise Linux AS 2.1 Netpbm Netpbm 10.29 Netpbm Netpbm 10.27 Netpbm Netpbm 10.26 Netpbm Netpbm 10.25 Netpbm Netpbm 10.14 Netpbm Netpbm 10.13 Netpbm Netpbm 10.12 Netpbm Netpbm 10.11 Netpbm Netpbm 10.10 Netpbm Netpbm 10.0 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Conectiva Linux 10.0 |
| Not Vulnerable: | |
Discussion
NetPBM PNMToPNG Buffer Overflow Vulnerability
pnmtopng is susceptible to a buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer. This issue reportedly only occurs when the '-trans' command line option is utilized.
This issue allows attackers to create malicious PNM files, that when parsed by the affected utility, allow arbitrary machine code to be executed. This occurs in the context of the user running the affected utility.
This vulnerability was reported in version 10.0 of NetPBM. Other versions may also be affected.
pnmtopng is susceptible to a buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer. This issue reportedly only occurs when the '-trans' command line option is utilized.
This issue allows attackers to create malicious PNM files, that when parsed by the affected utility, allow arbitrary machine code to be executed. This occurs in the context of the user running the affected utility.
This vulnerability was reported in version 10.0 of NetPBM. Other versions may also be affected.
Exploit / POC
NetPBM PNMToPNG Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
NetPBM PNMToPNG Buffer Overflow Vulnerability
Solution:
Ubuntu has released advisory USN-210-1, along with fixes to address this issue. Please see the referenced advisory for further information.
RedHat has released advisory RHSA-2005:793-6, along with fixes to address this issue in RedHat Enterprise Linux 4 operating systems. Please see the referenced advisories for further information.
Gentoo has released advisory GLSA 200510-18 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=media-libs/netpbm-10.29"
SUSE Linux has released security advisory SUSE-SR:2005:024 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Mandriva has released advisory MDKSA-2005:199 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Debian has released advisory DSA 878-1 and fixes to address this issue. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Conectiva Linux 10.0
Netpbm Netpbm 10.10
SGI ProPack 3.0 SP6
Solution:
Ubuntu has released advisory USN-210-1, along with fixes to address this issue. Please see the referenced advisory for further information.
RedHat has released advisory RHSA-2005:793-6, along with fixes to address this issue in RedHat Enterprise Linux 4 operating systems. Please see the referenced advisories for further information.
Gentoo has released advisory GLSA 200510-18 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=media-libs/netpbm-10.29"
SUSE Linux has released security advisory SUSE-SR:2005:024 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Mandriva has released advisory MDKSA-2005:199 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Debian has released advisory DSA 878-1 and fixes to address this issue. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Conectiva Linux 10.0
-
Conectiva postgresql-7.4.2-57056U10_1cl.i386.rpm
Conectiva 10
ftp://atualizacoes.conectiva.com.br/10/RPMS/postgresql-7.4.2-57056U10_ 1cl.i386.rpm -
Conectiva postgresql-clients-7.4.2-57056U10_1cl.i386.rpm
Conectiva 10
ftp://atualizacoes.conectiva.com.br/10/RPMS/postgresql-clients-7.4.2-5 7056U10_1cl.i386.rpm -
Conectiva postgresql-contrib-7.4.2-57056U10_1cl.i386.rpm
Conectiva 10
ftp://atualizacoes.conectiva.com.br/10/RPMS/postgresql-contrib-7.4.2-5 7056U10_1cl.i386.rpm -
Conectiva postgresql-devel-static-7.4.2-57056U10_1cl.i386.rpm
Conectiva 10
ftp://atualizacoes.conectiva.com.br/10/RPMS/postgresql-devel-static-7. 4.2-57056U10_1cl.i386.rpm -
Conectiva postgresql-doc-7.4.2-57056U10_1cl.i386.rpm
Conectiva 10
ftp://atualizacoes.conectiva.com.br/10/RPMS/postgresql-doc-7.4.2-57056 U10_1cl.i386.rpm -
Conectiva postgresql-tcl-7.4.2-57056U10_1cl.i386.rpm
Conectiva 10
ftp://atualizacoes.conectiva.com.br/10/RPMS/postgresql-tcl-7.4.2-57056 U10_1cl.i386.rpm -
Conectiva postgresql-test-7.4.2-57056U10_1cl.i386.rpm
Conectiva 10
ftp://atualizacoes.conectiva.com.br/10/RPMS/postgresql-test-7.4.2-5705 6U10_1cl.i386.rpm
Netpbm Netpbm 10.10
-
Ubuntu libnetpbm10-dev_10.0-5ubuntu0.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm10- dev_10.0-5ubuntu0.1_amd64.deb -
Ubuntu libnetpbm10-dev_10.0-5ubuntu0.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm10- dev_10.0-5ubuntu0.1_i386.deb -
Ubuntu libnetpbm10-dev_10.0-5ubuntu0.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm10- dev_10.0-5ubuntu0.1_powerpc.deb -
Ubuntu libnetpbm10-dev_10.0-8ubuntu0.1_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm10- dev_10.0-8ubuntu0.1_amd64.deb -
Ubuntu libnetpbm10-dev_10.0-8ubuntu0.1_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm10- dev_10.0-8ubuntu0.1_i386.deb -
Ubuntu libnetpbm10-dev_10.0-8ubuntu0.1_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm10- dev_10.0-8ubuntu0.1_powerpc.deb -
Ubuntu libnetpbm10_10.0-5ubuntu0.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm10_ 10.0-5ubuntu0.1_amd64.deb -
Ubuntu libnetpbm10_10.0-5ubuntu0.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm10_ 10.0-5ubuntu0.1_i386.deb -
Ubuntu libnetpbm10_10.0-5ubuntu0.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm10_ 10.0-5ubuntu0.1_powerpc.deb -
Ubuntu libnetpbm10_10.0-8ubuntu0.1_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm10_ 10.0-8ubuntu0.1_amd64.deb -
Ubuntu libnetpbm10_10.0-8ubuntu0.1_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm10_ 10.0-8ubuntu0.1_i386.deb -
Ubuntu libnetpbm10_10.0-8ubuntu0.1_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm10_ 10.0-8ubuntu0.1_powerpc.deb -
Ubuntu libnetpbm9-dev_10.0-5ubuntu0.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm9-d ev_10.0-5ubuntu0.1_amd64.deb -
Ubuntu libnetpbm9-dev_10.0-5ubuntu0.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm9-d ev_10.0-5ubuntu0.1_i386.deb -
Ubuntu libnetpbm9-dev_10.0-5ubuntu0.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm9-d ev_10.0-5ubuntu0.1_powerpc.deb -
Ubuntu libnetpbm9-dev_10.0-8ubuntu0.1_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm9-d ev_10.0-8ubuntu0.1_amd64.deb -
Ubuntu libnetpbm9-dev_10.0-8ubuntu0.1_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm9-d ev_10.0-8ubuntu0.1_i386.deb -
Ubuntu libnetpbm9-dev_10.0-8ubuntu0.1_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm9-d ev_10.0-8ubuntu0.1_powerpc.deb -
Ubuntu libnetpbm9_10.0-5ubuntu0.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm9_1 0.0-5ubuntu0.1_amd64.deb -
Ubuntu libnetpbm9_10.0-5ubuntu0.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm9_1 0.0-5ubuntu0.1_i386.deb -
Ubuntu libnetpbm9_10.0-5ubuntu0.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm9_1 0.0-5ubuntu0.1_powerpc.deb -
Ubuntu libnetpbm9_10.0-8ubuntu0.1_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm9_1 0.0-8ubuntu0.1_amd64.deb -
Ubuntu libnetpbm9_10.0-8ubuntu0.1_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm9_1 0.0-8ubuntu0.1_i386.deb -
Ubuntu libnetpbm9_10.0-8ubuntu0.1_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/libnetpbm9_1 0.0-8ubuntu0.1_powerpc.deb -
Ubuntu netpbm_10.0-5ubuntu0.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/netpbm_10.0- 5ubuntu0.1_amd64.deb -
Ubuntu netpbm_10.0-5ubuntu0.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/netpbm_10.0- 5ubuntu0.1_i386.deb -
Ubuntu netpbm_10.0-5ubuntu0.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/netpbm_10.0- 5ubuntu0.1_powerpc.deb -
Ubuntu netpbm_10.0-8ubuntu0.1_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/netpbm_10.0- 8ubuntu0.1_amd64.deb -
Ubuntu netpbm_10.0-8ubuntu0.1_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/netpbm_10.0- 8ubuntu0.1_i386.deb -
Ubuntu netpbm_10.0-8ubuntu0.1_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/n/netpbm-free/netpbm_10.0- 8ubuntu0.1_powerpc.deb
SGI ProPack 3.0 SP6
-
SGI Patch 10212
http://support.sgi.com/
References
NetPBM PNMToPNG Buffer Overflow Vulnerability
References:
References: