PDA

View Full Version : Exploit in libPNG


fantasyx72
06-03-2007, 11:51 PM
There has been an exploit found in libpng <= 1.2.16. A vulnerability has been found allowing the execution of a Denial Of Service Attack. Its just a of hope for all PSP firmware 3.03 and above owners


Heres more links
http://forums.qj.net/f-psp-speculation-24/t-exploit-in-libpng-don
t-get-too-happy-109009.html
http://forums.maxconsole.net/showthread.php?p=547859#post547859

Darkchild
06-04-2007, 06:24 PM
this is quite huge :O still...if it doesn't even run a hello world program..won't do nothing...and according to what I read it only makes the PSP crash

x3sphere
06-04-2007, 06:50 PM
Someone sent this in a few days ago but I never reported on it because I'd hate to get users hopes up for nothing.

The exploit, only creates a DoS condition, which could be used to crash a program. It cannot run any arbitrary code, and that's why it is classified as a Low Risk.

Chilly Willy
06-04-2007, 07:24 PM
Someone sent this in a few days ago but I never reported on it because I'd hate to get users hopes up for nothing.

The exploit, only creates a DoS condition, which could be used to crash a program. It cannot run any arbitrary code, and that's why it is classified as a Low Risk.

Which is why it can't be used for a downgrader. You need a buffer overflow exploit for a downgrader.

Darkchild
06-04-2007, 08:11 PM
[...]and according to what I read it only makes the PSP crash

I think I summed it up right there xD

Mathieulh
06-08-2007, 10:45 PM
Yes this exploit cannot be used to run proper code on a psp, beside even if it could you cannot code a downgrader with only a user mode exploit, you need a priviledge escalation exploit that allows to run kernel mode code from the user mode exploit you'd possibly find, otherwise, no downgrader.