xvpng.c in xv 3.10a has memory corruption (out-of-bounds write) when decoding PNG comment fields, leading to crashes or potentially code execution, because it uses an incorrect length value.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://bugzilla.suse.com/attachment.cgi?id=728337 | issue tracking third party advisory |
https://lists.opensuse.org/opensuse-updates/2018-02/msg00088.html | third party advisory mailing list |
https://bugzilla.suse.com/show_bug.cgi?id=1043479 | issue tracking third party advisory |