Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

openSUSE: 2015:2099-1 Important: Buffer Overflow and Out-of-Bounds Fix

opensuse
Calendar Grey November 25, 2015
Scroller Opensuse
The latest openSUSE update tackles significant libpng12 concerns, specifically targeting vulnerabilities related to buffer overflows and out-of-bounds read operations.
An update that fixes two vulnerabilities is now available

Description

The libpng12 package was updated to fix the following security issues:

- CVE-2015-8126: Fixed a buffer overflow vulnerabilities in

png_get_PLTE/png_set_PLTE functions (bsc#954980).

- CVE-2015-7981: Fixed an out-of-bound read (bsc#952051).

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.2:

zypper in -t patch openSUSE-2015-802=1

- openSUSE 13.1:

zypper in -t patch openSUSE-2015-802=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.2 (i586 x86_64):

libpng12-0-1.2.51-3.3.1

libpng12-0-debuginfo-1.2.51-3.3.1

libpng12-compat-devel-1.2.51-3.3.1

libpng12-debugsource-1.2.51-3.3.1

libpng12-devel-1.2.51-3.3.1

- openSUSE 13.2 (x86_64):

libpng12-0-32bit-1.2.51-3.3.1

libpng12-0-debuginfo-32bit-1.2.51-3.3.1

libpng12-compat-devel-32bit-1.2.51-3.3.1

libpng12-devel-32bit-1.2.51-3.3.1

- openSUSE 13.1 (i586 x86_64):

libpng12-0-1.2.50-6.7.1

libpng12-0-debuginfo-1.2.50-6.7.1

libpng12-compat-devel-1.2.50-6.7.1

libpng12-debugsource-1.2.50-6.7.1

libpng12-devel-1.2.50-6.7.1

- openSUSE 13.1 (x86_64):

libpng12-0-32bit-1.2.50-6.7.1

libpng12-0-debuginfo-32bit-1.2.50-6.7.1

libpng12-compat-devel-32bit-1.2.50-6.7.1

libpng12-devel-32bit-1.2.50-6.7.1

References

https://www.suse.com/security/cve/CVE-2015-7981.html

https://www.suse.com/security/cve/CVE-2015-8126.html

https://bugzilla.suse.com/show_bug.cgi?id=952051

https://bugzilla.suse.com/show_bug.cgi?id=954980

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2015:2099-1
Rating: important
Affected Products: openSUSE 13.2 openSUSE 13.1 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.