Critical PNG Flaw Haunts Netscape

Critical PNG Flaw Haunts Netscape

Written By
Ryan Naraine
Ryan Naraine
Dec 1, 2004
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

America Online Inc.s efforts to kick-start renewed interest in its Netscape browser got off to a rocky start with researchers warning of a “highly critical” flaw that could lead to remote code execution.

Just 24 hours after AOL unveiled a new Netscape prototype, Sun Microsystems Inc. issued an advisory for multiple vulnerabilities in the way the browser handles PNG (portable network graphic) images.

The bug, which affects Netscape 7.x, is directly related to the previously reported buffer overflows in the PNG Library (libpng) that is used to manipulate PNG files.

/zimages/2/28571.gifClick hereto read more about the flaws in the PNG library.

Sun said the flaw puts Netscape users at risk of remote code execution attacks.

“This condition can be exploited when the local user has loaded a Portable Network Graphics (PNG) format image file supplied by an untrusted user and views a malicious web site or views an e-mail message containing a malformed PNG image with that application,” according to the Sun advisory.

The affected Netscape 7 is shipped in Suns Solaris 9. It was also available for Solaris 7, 8 and 9 as part of the SUNWnsb package, Sun said.

Independent research firm Secunia rates the issue as “highly critical” and recommends users use another browser until a patch is made available.

AOL spokesman Andrew Weinstein declined to comment until the company has time to investigate the Sun advisory.

/zimages/2/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.