Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Fedora 27: Security Advisory for OptiPNG Critical Threats

fedora
Calendar Grey December 19, 2017
Dist Fedora Esm H88
Fedora 27 receives an OptiPNG update tackling urgent vulnerabilities such as memory corruption and potential execution exploits.
Security fix for CVE-2017-1000229 and CVE-2017-16938

Summary

OptiPNG is a PNG optimizer that recompresses image files to a smaller size,

without losing any information. This program also converts external formats

(BMP, GIF, PNM and TIFF) to optimized PNG, and performs PNG integrity checks

and corrections.

Security fix for CVE-2017-1000229 and CVE-2017-16938

[ 1 ] Bug #1520234 - CVE-2017-1000229 optipng: integer overflow in tiffread.c:minitiff_read_info() allows for arbitrary code execution

https://bugzilla.redhat.com/show_bug.cgi?id=1520234

[ 2 ] Bug #1520227 - CVE-2017-16938 optipng: global buffer overflow in gifread.c:LZWReadByte when parsing malicious GIF

https://bugzilla.redhat.com/show_bug.cgi?id=1520227

su -c 'dnf upgrade optipng' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 27
Version: 0.7.6
Release: 5.fc27
Summary: PNG optimizer and converter

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here