Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2005:793 - Security Advisory
Issued:
2005-10-18
Updated:
2005-10-18

RHSA-2005:793 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

netpbm security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Updated netpbm packages that fix a security issue are now available.

This update has been rated as having moderate security impact by the Red Hat
Security Response Team.

Description

The netpbm package contains a library of functions that support
programs for handling various graphics file formats, including .pbm
(portable bitmaps), .pgm (portable graymaps), .pnm (portable anymaps),
.ppm (portable pixmaps) and others.

A bug was found in the way netpbm converts Portable Anymap (PNM) files into
Portable Network Graphics (PNG). The usage of uninitialised variables in
the pnmtopng code allows an attacker to change stack contents when
converting to PNG files with pnmtopng using the '-trans' option. This may
allow an attacker to execute arbitrary code. The Common Vulnerabilities
and Exposures project assigned the name CAN-2005-2978 to this issue.

All users of netpbm should upgrade to the updated packages, which
contain a backported patch to resolve this issue.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

This update is available via Red Hat Network. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Affected Products

  • Red Hat Enterprise Linux Server 4 x86_64
  • Red Hat Enterprise Linux Server 4 ia64
  • Red Hat Enterprise Linux Server 4 i386
  • Red Hat Enterprise Linux Workstation 4 x86_64
  • Red Hat Enterprise Linux Workstation 4 ia64
  • Red Hat Enterprise Linux Workstation 4 i386
  • Red Hat Enterprise Linux Desktop 4 x86_64
  • Red Hat Enterprise Linux Desktop 4 i386
  • Red Hat Enterprise Linux for IBM z Systems 4 s390x
  • Red Hat Enterprise Linux for IBM z Systems 4 s390
  • Red Hat Enterprise Linux for Power, big endian 4 ppc

Fixes

  • BZ - 168278 - CAN-2005-2978 Crash running pnmtopng -trans on some pnm files

CVEs

  • CVE-2005-2978

References

(none)

Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server 4

SRPM
netpbm-10.25-2.EL4.2.src.rpm SHA-256: 874426479a283b48bb8bc1bd3170c805c4b817790e48afc9e3cfa1c712116759
x86_64
netpbm-10.25-2.EL4.2.i386.rpm SHA-256: 6ebf3b9d5068af69adb2955336c07095b36baf938ee5d0c42548467ab262838e
netpbm-10.25-2.EL4.2.i386.rpm SHA-256: 6ebf3b9d5068af69adb2955336c07095b36baf938ee5d0c42548467ab262838e
netpbm-10.25-2.EL4.2.x86_64.rpm SHA-256: e0f2df31d34eb1e77eb4bed620862e10f22d70a50a5efb125e0f5fd186af6cd2
netpbm-10.25-2.EL4.2.x86_64.rpm SHA-256: e0f2df31d34eb1e77eb4bed620862e10f22d70a50a5efb125e0f5fd186af6cd2
netpbm-devel-10.25-2.EL4.2.x86_64.rpm SHA-256: 5daaacc8e05eff7cbac4f792dc9ebfd74434a23db11d6e7caae972a41fc3301e
netpbm-devel-10.25-2.EL4.2.x86_64.rpm SHA-256: 5daaacc8e05eff7cbac4f792dc9ebfd74434a23db11d6e7caae972a41fc3301e
netpbm-progs-10.25-2.EL4.2.x86_64.rpm SHA-256: 70006d7021b60e5ec983a33da5874df7dd8a33e8e55f5a6b1100734d8aa4401d
netpbm-progs-10.25-2.EL4.2.x86_64.rpm SHA-256: 70006d7021b60e5ec983a33da5874df7dd8a33e8e55f5a6b1100734d8aa4401d
ia64
netpbm-10.25-2.EL4.2.i386.rpm SHA-256: 6ebf3b9d5068af69adb2955336c07095b36baf938ee5d0c42548467ab262838e
netpbm-10.25-2.EL4.2.i386.rpm SHA-256: 6ebf3b9d5068af69adb2955336c07095b36baf938ee5d0c42548467ab262838e
netpbm-10.25-2.EL4.2.ia64.rpm SHA-256: b358080f02afd237ba89bbdcd70f651fb1405ceaec55c7d16302753ae601ea00
netpbm-10.25-2.EL4.2.ia64.rpm SHA-256: b358080f02afd237ba89bbdcd70f651fb1405ceaec55c7d16302753ae601ea00
netpbm-devel-10.25-2.EL4.2.ia64.rpm SHA-256: 7bb4c6609b10e08cb11f90f2890197265e8c29a650ffa5a050447a77b6a3c561
netpbm-devel-10.25-2.EL4.2.ia64.rpm SHA-256: 7bb4c6609b10e08cb11f90f2890197265e8c29a650ffa5a050447a77b6a3c561
netpbm-progs-10.25-2.EL4.2.ia64.rpm SHA-256: 9a945b41810d596ad7a440e905abbf96daa114cd4aa1f2a2526426d3b61343c8
netpbm-progs-10.25-2.EL4.2.ia64.rpm SHA-256: 9a945b41810d596ad7a440e905abbf96daa114cd4aa1f2a2526426d3b61343c8
i386
netpbm-10.25-2.EL4.2.i386.rpm SHA-256: 6ebf3b9d5068af69adb2955336c07095b36baf938ee5d0c42548467ab262838e
netpbm-10.25-2.EL4.2.i386.rpm SHA-256: 6ebf3b9d5068af69adb2955336c07095b36baf938ee5d0c42548467ab262838e
netpbm-devel-10.25-2.EL4.2.i386.rpm SHA-256: 517df54ed15278ad0eefd39b9d853e3f36aa73d8eb9622689d4bf53198096f78
netpbm-devel-10.25-2.EL4.2.i386.rpm SHA-256: 517df54ed15278ad0eefd39b9d853e3f36aa73d8eb9622689d4bf53198096f78
netpbm-progs-10.25-2.EL4.2.i386.rpm SHA-256: 2bab9dd3b7a5bb5e9c795363d36a2fbf2380267b6fa3d92f687d2a56a265874a
netpbm-progs-10.25-2.EL4.2.i386.rpm SHA-256: 2bab9dd3b7a5bb5e9c795363d36a2fbf2380267b6fa3d92f687d2a56a265874a

Red Hat Enterprise Linux Workstation 4

SRPM
netpbm-10.25-2.EL4.2.src.rpm SHA-256: 874426479a283b48bb8bc1bd3170c805c4b817790e48afc9e3cfa1c712116759
x86_64
netpbm-10.25-2.EL4.2.i386.rpm SHA-256: 6ebf3b9d5068af69adb2955336c07095b36baf938ee5d0c42548467ab262838e
netpbm-10.25-2.EL4.2.x86_64.rpm SHA-256: e0f2df31d34eb1e77eb4bed620862e10f22d70a50a5efb125e0f5fd186af6cd2
netpbm-devel-10.25-2.EL4.2.x86_64.rpm SHA-256: 5daaacc8e05eff7cbac4f792dc9ebfd74434a23db11d6e7caae972a41fc3301e
netpbm-progs-10.25-2.EL4.2.x86_64.rpm SHA-256: 70006d7021b60e5ec983a33da5874df7dd8a33e8e55f5a6b1100734d8aa4401d
ia64
netpbm-10.25-2.EL4.2.i386.rpm SHA-256: 6ebf3b9d5068af69adb2955336c07095b36baf938ee5d0c42548467ab262838e
netpbm-10.25-2.EL4.2.ia64.rpm SHA-256: b358080f02afd237ba89bbdcd70f651fb1405ceaec55c7d16302753ae601ea00
netpbm-devel-10.25-2.EL4.2.ia64.rpm SHA-256: 7bb4c6609b10e08cb11f90f2890197265e8c29a650ffa5a050447a77b6a3c561
netpbm-progs-10.25-2.EL4.2.ia64.rpm SHA-256: 9a945b41810d596ad7a440e905abbf96daa114cd4aa1f2a2526426d3b61343c8
i386
netpbm-10.25-2.EL4.2.i386.rpm SHA-256: 6ebf3b9d5068af69adb2955336c07095b36baf938ee5d0c42548467ab262838e
netpbm-devel-10.25-2.EL4.2.i386.rpm SHA-256: 517df54ed15278ad0eefd39b9d853e3f36aa73d8eb9622689d4bf53198096f78
netpbm-progs-10.25-2.EL4.2.i386.rpm SHA-256: 2bab9dd3b7a5bb5e9c795363d36a2fbf2380267b6fa3d92f687d2a56a265874a

Red Hat Enterprise Linux Desktop 4

SRPM
netpbm-10.25-2.EL4.2.src.rpm SHA-256: 874426479a283b48bb8bc1bd3170c805c4b817790e48afc9e3cfa1c712116759
x86_64
netpbm-10.25-2.EL4.2.i386.rpm SHA-256: 6ebf3b9d5068af69adb2955336c07095b36baf938ee5d0c42548467ab262838e
netpbm-10.25-2.EL4.2.x86_64.rpm SHA-256: e0f2df31d34eb1e77eb4bed620862e10f22d70a50a5efb125e0f5fd186af6cd2
netpbm-devel-10.25-2.EL4.2.x86_64.rpm SHA-256: 5daaacc8e05eff7cbac4f792dc9ebfd74434a23db11d6e7caae972a41fc3301e
netpbm-progs-10.25-2.EL4.2.x86_64.rpm SHA-256: 70006d7021b60e5ec983a33da5874df7dd8a33e8e55f5a6b1100734d8aa4401d
i386
netpbm-10.25-2.EL4.2.i386.rpm SHA-256: 6ebf3b9d5068af69adb2955336c07095b36baf938ee5d0c42548467ab262838e
netpbm-devel-10.25-2.EL4.2.i386.rpm SHA-256: 517df54ed15278ad0eefd39b9d853e3f36aa73d8eb9622689d4bf53198096f78
netpbm-progs-10.25-2.EL4.2.i386.rpm SHA-256: 2bab9dd3b7a5bb5e9c795363d36a2fbf2380267b6fa3d92f687d2a56a265874a

Red Hat Enterprise Linux for IBM z Systems 4

SRPM
netpbm-10.25-2.EL4.2.src.rpm SHA-256: 874426479a283b48bb8bc1bd3170c805c4b817790e48afc9e3cfa1c712116759
s390x
netpbm-10.25-2.EL4.2.s390.rpm SHA-256: f4efa84768d06d8dc558da4bfbf1f85e8d93ab2e8b1897e98bd4a2f660797414
netpbm-10.25-2.EL4.2.s390x.rpm SHA-256: 42081cc82f5fefdd0ebcc0704b1e2538eeaddeeefff7af92d07cbf8791fe2ee6
netpbm-devel-10.25-2.EL4.2.s390x.rpm SHA-256: 9a5843ef2ceab49478554d1cb6695be24a82ff933cad08144408f0a01853b1cd
netpbm-progs-10.25-2.EL4.2.s390x.rpm SHA-256: 458025c7616c77fc2229f43b102ceb6617709d670f2153ceae26975197055101
s390
netpbm-10.25-2.EL4.2.s390.rpm SHA-256: f4efa84768d06d8dc558da4bfbf1f85e8d93ab2e8b1897e98bd4a2f660797414
netpbm-devel-10.25-2.EL4.2.s390.rpm SHA-256: 6d3bdeaf8d99b80505c30b638b8df765c9e84f1f2624a1a7eabba73a447959fd
netpbm-progs-10.25-2.EL4.2.s390.rpm SHA-256: 4d6cc2a70ce721d5c0d0b2dfbf7742679290f8fca8e2cf40d753ef76730637d0

Red Hat Enterprise Linux for Power, big endian 4

SRPM
netpbm-10.25-2.EL4.2.src.rpm SHA-256: 874426479a283b48bb8bc1bd3170c805c4b817790e48afc9e3cfa1c712116759
ppc
netpbm-10.25-2.EL4.2.ppc.rpm SHA-256: e438014db26e7daeb78250331f1359a83b24fb99bb341b0c501bfcddd8e303f0
netpbm-10.25-2.EL4.2.ppc64.rpm SHA-256: 79bd647da19baa5fd342c72800c9eb3c014307900c18fdb080a6a06ef64e245f
netpbm-devel-10.25-2.EL4.2.ppc.rpm SHA-256: ff71675a313d0d1610eb8f371549e0978df3e0795c8c0bd5a683e6364501ac41
netpbm-progs-10.25-2.EL4.2.ppc.rpm SHA-256: 4ae44892f48d271de46315eb697d11dc7b7992274fbda7f33537d073a4d0efe2

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility