Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2005:217: netpbm Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the netpbm package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2005:217 (netpbm).
Greg Roelofs discovered and fixed several buffer overflows in pnmtopng which is
also included in netpbm, a collection of graphic conversion utilities, that can
lead to the execution of arbitrary code via a specially crafted PNM file.
Multiple buffer overflows in pnmtopng in netpbm 10.0 and earlier allow
attackers to execute arbitrary code via a crafted PNM file. (CVE-2005-3632) An
off-by-one buffer overflow in pnmtopng, when using the -alpha command line
option, allows attackers to cause a denial of service (crash) and possibly
execute arbitrary code via a crafted PNM file with exactly 256 colors.
(CVE-2005-3662) The updated packages have been patched to correct this problem.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:217
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.