ALAS2-2019-1313

Related Vulnerabilities: CVE-2016-2191  

The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a crafted BMP image.(CVE-2016-2191)

ALAS2-2019-1313


Amazon Linux 2 Security Advisory: ALAS-2019-1313
Advisory Release Date: 2019-10-08 22:03 Pacific
Advisory Updated Date: 2019-10-09 23:22 Pacific
Severity: Medium
References: CVE-2016-2191 

Issue Overview:

The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a crafted BMP image.(CVE-2016-2191)


Affected Packages:

optipng


Issue Correction:
Run yum update optipng to update your system.

New Packages:
aarch64:
    optipng-0.7.7-3.amzn2.aarch64
    optipng-debuginfo-0.7.7-3.amzn2.aarch64

i686:
    optipng-0.7.7-3.amzn2.i686
    optipng-debuginfo-0.7.7-3.amzn2.i686

src:
    optipng-0.7.7-3.amzn2.src

x86_64:
    optipng-0.7.7-3.amzn2.x86_64
    optipng-debuginfo-0.7.7-3.amzn2.x86_64