Details on Apple's Security Update 2004-08-09
The update fixes the portable network graphics (PNG) vulnerability we noted last Friday and it is available via the Software Update preference pane or as a standalone updater for 10.2.8 or 10.3.4. The Read Me file states:
Security Update 2004-08-09 delivers a number of security enhancements and is recommended for all Macintosh users. This update includes the following components:
libpng (Portable Network Graphics)
The details are:
libpng (Portable Network Graphics) Fixes CAN-2002-1363, CAN-2004-0421, CAN-2004-0597, CAN-2004-0598, CAN-2004-0599
Impact: Malicious PNG images can cause application crashes and could execute arbitrary code
Description: A number of buffer overflows, null pointer dereferences and integer overflows have been discovered in the reference library for reading and writing PNG images. These vulnerabilities have been corrected in libpng which is used by the CoreGraphics and AppKit frameworks in Mac OS X. After installing this update, applications that use the PNG image format via these frameworks will be protected against these flaws.
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?