-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-6603 2009-06-18 11:00:48 -------------------------------------------------------------------------------- Name : libpng Product : Fedora 9 Version : 1.2.37 Release : 1.fc9 URL : https://www.libpng.org/pub/png/ Summary : A library of functions for manipulating PNG image format files Description : The libpng package contains a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. PNG is a bit-mapped graphics format similar to the GIF format. PNG was created to replace the GIF format, since GIF uses a patented data compression algorithm. Libpng should be installed if you need to manipulate PNG format image files. -------------------------------------------------------------------------------- Update Information: Update to libpng 1.2.37, to fix CVE-2009-2042. This is a pretty low-risk issue, but it's been classified as a security issue... -------------------------------------------------------------------------------- ChangeLog: * Sat Jun 13 2009 Tom Lane2:1.2.37-1 - Update to libpng 1.2.37, to fix CVE-2009-2042 Related: #504782 * Wed Feb 25 2009 Tom Lane 2:1.2.35-1 - Update to libpng 1.2.35, to fix CVE-2009-0040 * Fri Jan 9 2009 Tom Lane 2:1.2.34-1 - Update to libpng 1.2.34 * Sun Nov 2 2008 Tom Lane 2:1.2.33-1 - Update to libpng 1.2.33 * Sat May 31 2008 Tom Lane 2:1.2.29-1 - Update to libpng 1.2.29 (fixes low-priority security issue CVE-2008-1382) Related: #441839 -------------------------------------------------------------------------------- References: [ 1 ] Bug #504782 - libpng: Interlaced Images Information Disclosure Vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=504782 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libpng' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list Fedora-package-announce@redhat.com https://www.redhat.com/mailman/listinfo/fedora-package-announce