Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

Fedora 9 Libpng 1.2.37 Low Security Update: PNG Handling Issue

fedora
Calendar Grey June 18, 2009
Scroller Fedora
An upgrade to libpng 1.2.37 addresses a minor security vulnerability in Fedora 9 related to processing PNG images.
Update to libpng 1.2.37, to fix CVE-2009-2042

Summary

The libpng package contains a library of functions for creating and

manipulating PNG (Portable Network Graphics) image format files. PNG

is a bit-mapped graphics format similar to the GIF format. PNG was

created to replace the GIF format, since GIF uses a patented data

compression algorithm.

Libpng should be installed if you need to manipulate PNG format image

files.

Update Information:

Update to libpng 1.2.37, to fix CVE-2009-2042. This is a pretty low-risk issue, but it's been classified as a security issue...

Change Log

* Sat Jun 13 2009 Tom Lane 2:1.2.37-1 - Update to libpng 1.2.37, to fix CVE-2009-2042 Related: #504782 * Wed Feb 25 2009 Tom Lane 2:1.2.35-1 - Update to libpng 1.2.35, to fix CVE-2009-0040 * Fri Jan 9 2009 Tom Lane 2:1.2.34-1 - Update to libpng 1.2.34 * Sun Nov 2 2008 Tom Lane 2:1.2.33-1 - Update to libpng 1.2.33 * Sat May 31 2008 Tom Lane 2:1.2.29-1 - Update to libpng 1.2.29 (fixes low-priority security issue CVE-2008-1382) Related: #441839

References


[ 1 ] Bug #504782 - libpng: Interlaced Images Information Disclosure Vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=504782

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update libpng' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
low
Lowest
Low
Medium
High
Critical

Name: libpng
Product: Fedora 9
Version: 1.2.37
Release: 1.fc9
Summary: A library of functions for manipulating PNG image format files

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.