Digital Home Thoughts

Digital Home Thoughts - News & Reviews for the Digital Home

Register in our forums so you're ready for our next giveaway contest...





Go Back   Thoughts Media Forums > DIGITAL HOME THOUGHTS > Digital Home News

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-06-2004, 05:00 PM
Oracle
Join Date: Dec 2003
Posts: 911
Send a message via AIM to Kent Pribbernow Send a message via MSN to Kent Pribbernow
Default Six Security Vulnerabilities Found In PNG Graphic Format

http://news.com.com/Image+flaw+pierces+PC+security/2100-1002_3-5298999.html?tag=nefd.top

"Six vulnerabilities in an open-source image format could allow intruders to compromise computers running Linux and may allow attacks against Windows PCs as well as Macs running OS X. The security issues appear in a library supporting the portable network graphics (PNG) format, used widely by programs such as the Mozilla and Opera browsers and various e-mail clients. The most critical issue, a memory problem known as a buffer overflow, could allow specially created PNG graphics to execute a malicious program when the application loads the image."

This is rather disturbing news as PNG is one of the most popular graphics formats used on the web. Some web graphics design software like Macromedia Fireworks MX (a product that I use every day in my work 8O ) uses PNG as its native file format. The vulnerability could allow hackers to create malicious image files that web browsers would unwittingly download and execute, allowing the intruders access to your vital data.

Isn't the internet fun? :wink:
 
Reply With Quote
  #2 (permalink)  
Old 08-06-2004, 05:49 PM
Executive Editor
Jason Dunn's Avatar
Join Date: Aug 2006
Posts: 23,595

Is PNG really used all that often though? Myself, I never use it on Web pages - the advantages over GIFs and JPEGs are minimal. Alpha transparency on a 32-bit colour image is cool and all, but not if certain visitors can't see it.
 
Reply With Quote
  #3 (permalink)  
Old 08-06-2004, 08:08 PM
Thinker
Join Date: Mar 2004
Posts: 337

Quote:
Originally Posted by Jason Dunn
Is PNG really used all that often though? Myself, I never use it on Web pages - the advantages over GIFs and JPEGs are minimal. Alpha transparency on a 32-bit colour image is cool and all, but not if certain visitors can't see it.
Or most visitors! I've been redesigning the web site for my department and really needed good transparency (i.e. no GIF halo) and in a 24 bit image and so I tried out .png for the first time. It seemed great until I opened it up in Internet Explorer, where the alpha channel was a block of semi-transparent white instead of fully transparent. A quick Net search turned up that this is a known bug in IE that MS doesn't seemed very concerned about fixing. I don't know about your stats, but at my sites 92% of my visitors are IE users so using transparent .png is out of the question. Since that's the main reason why I would use .png, I just don't bother.

Of course, the security issue doesn't exactly make we want to run out and reconsider either!
 
Reply With Quote
  #4 (permalink)  
Old 08-06-2004, 09:55 PM
Intellectual
Join Date: Feb 2004
Posts: 201
Default Re: Six Security Vulnerabilities Found In PNG Graphic Format

Quote:
Originally Posted by Kent Pribbernow
Six Security Vulnerabilities Found In PNG Graphic Format
This title is a little misleading... the flaws are not the PNG files....
 
Reply With Quote
  #5 (permalink)  
Old 08-07-2004, 05:16 PM
Pupil
Join Date: Feb 2004
Posts: 33

I use Fireworks all of the time, and although its native format is PNG, I always export to gif or jpeg, so not a problem for me. However, the point that someone who does use png on a web page for malicious purposes is disturbing.

"Outlaw" hackers and spammers have certainly screwed up the Internet experience for everyone. Where I work as the webguy, our WAN staff finally had to turn of the ability to ping our servers because of attacks. I work off of our organization's campus so it kind of sucks when I want to do a quick check if I have a problem to see if the server may be down. Thanks, hackers.
 
Reply With Quote
  #6 (permalink)  
Old 08-09-2004, 12:43 AM
Editor Emeritus
Suhit Gupta's Avatar
Join Date: Aug 2006
Posts: 2,863
Default Re: Six Security Vulnerabilities Found In PNG Graphic Format

Quote:
Originally Posted by butch
Quote:
Originally Posted by Kent Pribbernow
Six Security Vulnerabilities Found In PNG Graphic Format
This title is a little misleading... the flaws are not the PNG files....
That is correct. The flaws are not in PNG files, instead they are in the reading libraries. The patches, AFAIK are already out for Redhat. Just do an up2date.

Suhit
 
Reply With Quote
  #7 (permalink)  
Old 08-10-2004, 01:23 AM
Theorist
Join Date: Apr 2004
Posts: 279
Default ...

This afternoon Apple released a software update patch that takes care of this issue. Just an FYI.

http://docs.info.apple.com/article.html?artnum=61798
 
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT +1. The time now is 10:42 PM.



Search Engine Friendly URLs by vBSEO 3.2.0 RC7