Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Slackware 10.2: SSA:2007-325-01a Critical Libpng Security Fix

slackware
Calendar Grey November 21, 2007
Dist Slackware Esm H88
An essential patch for libpng on Slackware 10.1 and 10.2 addresses major security flaws. Immediate upgrade is recommended.
New libpng packages are available for Slackware 10.1 and 10.2 that were left out of the last batch of updates

Summary

Here are the details from the Slackware 10.2 ChangeLog: patches/packages/libpng-1.2.23-i486-1_slack10.2.tgz: Upgraded to libpng-1.2.23. Previous libpng versions may crash when loading malformed PNG files. It is not currently known if this vulnerability can be exploited to execute malicious code. For more information, see: https://www.cve.org/CVERecord?id=CVE-2007-5266 https://www.cve.org/CVERecord?id=CVE-2007-5267 https://www.cve.org/CVERecord?id=CVE-2007-5268 https://www.cve.org/CVERecord?id=CVE-2007-5269 (* Security fix *)

Where Find New Packages

HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com.
Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 10.1:
Updated package for Slackware 10.2:

MD5 Signatures

Slackware 10.1 package: ceb264e9db70c30832fff54c127650fb libpng-1.2.23-i486-1_slack10.1.tgz
Slackware 10.2 package: 16006289974b45f6fc2d1f1330dc2231 libpng-1.2.23-i486-1_slack10.2.tgz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the packages as root: # upgradepkg libpng-1.2.23-i486-1_slack10.2.tgz Applications that use libpng may have to be restarted.

Your message here