Debian Security Advisory
DSA-4058-1 optipng -- security update
- Date Reported:
- 08 Dec 2017
- Affected Packages:
- optipng
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 878839, Bug 882032.
In Mitre's CVE dictionary: CVE-2017-16938, CVE-2017-1000229. - More information:
-
Two vulnerabilities were discovered in optipng, an advanced PNG optimizer, which may result in denial of service or the execution of arbitrary code if a malformed file is processed.
For the oldstable distribution (jessie), these problems have been fixed in version 0.7.5-1+deb8u2.
For the stable distribution (stretch), these problems have been fixed in version 0.7.6-1+deb9u1.
We recommend that you upgrade your optipng packages.
For the detailed security status of optipng please refer to its security tracker page at: https://security-tracker.debian.org/tracker/optipng