Upgrade PNG library to fix memory safety hazards

Related Vulnerabilities: CVE-2009-0040  

Mozilla Foundation Security Advisory 2009-10

Upgrade PNG library to fix memory safety hazards

Announced
March 4, 2009
Reporter
Tavis Ormandy
Impact
Critical
Products
Firefox, SeaMonkey, Thunderbird
Fixed in
  • Firefox 3.0.7
  • SeaMonkey 1.1.15
  • Thunderbird 2.0.0.21

Description

Google security researcher Tavis Ormandy reported several memory safety hazards to the libpng project, an external library used by Mozilla to render PNG images. These vulnerabilities could be used by a malicious website to crash a victim's browser and potentially execute arbitrary code on their computer. libpng was upgraded to version 1.2.35 which containis fixes for these flaws.

References