Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 28: 2018-04eded822e Critical: libpng10 Integer Overflow DoS

Fix for CVE-2018-13785: the libpng10 library was vulnerable to an integer overflow and resultant divide-by-zero in the pngrutil.c:png_check_chunk_length() function. An attacker could exploit this to cause a denial of service via a crafted PNG file.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-04eded822e 2018-07-29 03:19:11.836325 --------------------------------------------------------------------------------Name : libpng10 Product : Fedora 28 Version : 1.0.69 Release : 5.fc28 URL : http://www.libpng.org/pub/png/libpng.html Summary : Old version of libpng, needed to run old binaries Description : The libpng10 package contains an old version of libpng, a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. This package is needed if you want to run binaries that were linked dynamically with libpng 1.0.x. --------------------------------------------------------------------------------Update Information: Fix for CVE-2018-13785: the libpng10 library was vulnerable to an integer overflow and resultant divide-by-zero in the pngrutil.c:png_check_chunk_length() function. An attacker could exploit this to cause a denial of service via a crafted PNG file. --------------------------------------------------------------------------------ChangeLog: * Fri Jul 13 2018 Paul Howarth - 1.0.69-5 - Fix the calculation of row_factor in png_check_chunk_length (CVE-2018-13785) * Fri Jul 13 2018 Fedora Release Engineering - 1.0.69-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1599943 - CVE-2018-13785 libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service https://bugzilla.redhat.com/show_bug.cgi?id=1599943 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-04eded822e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/RZ3N4X57QBQK7RIBYBEVPEKUSDHFALEV/ . Mitigating integer overflow concerns in libpng10 for Fedora 28, this patch blocks potential denial of service attacks via specially designed PNG files.. libpng10 Update,Fedora 28 Security,Denial Of Service Fix,Integer Overflow Risk. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 29, 2018 Critical Fedora
89

Fedora 27 update: libpng10 Denial Of Service advisory for CVE-2018-13785

Fix for CVE-2018-13785: the libpng10 library was vulnerable to an integer overflow and resultant divide-by-zero in the pngrutil.c:png_check_chunk_length() function. An attacker could exploit this to cause a denial of service via a crafted PNG file.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-3e04e9fe54 2018-07-29 02:18:19.405657 --------------------------------------------------------------------------------Name : libpng10 Product : Fedora 27 Version : 1.0.69 Release : 5.fc27 URL : http://www.libpng.org/pub/png/libpng.html Summary : Old version of libpng, needed to run old binaries Description : The libpng10 package contains an old version of libpng, a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. This package is needed if you want to run binaries that were linked dynamically with libpng 1.0.x. --------------------------------------------------------------------------------Update Information: Fix for CVE-2018-13785: the libpng10 library was vulnerable to an integer overflow and resultant divide-by-zero in the pngrutil.c:png_check_chunk_length() function. An attacker could exploit this to cause a denial of service via a crafted PNG file. --------------------------------------------------------------------------------ChangeLog: * Fri Jul 13 2018 Paul Howarth - 1.0.69-5 - Fix the calculation of row_factor in png_check_chunk_length (CVE-2018-13785) * Fri Jul 13 2018 Fedora Release Engineering - 1.0.69-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Wed Feb 14 2018 Paul Howarth - 1.0.69-3 - Avoid use of arch-specific build-requires (#1545195) * Tue Feb 6 2018 Paul Howarth - 1.0.69-2 - ldconfig scriptlets replaced by RPM File Triggers from Fedora 28 - Make zlib-devel dependencies arch-specific - Preserve upstream timestamps wherepossible --------------------------------------------------------------------------------References: [ 1 ] Bug #1599943 - CVE-2018-13785 libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service https://bugzilla.redhat.com/show_bug.cgi?id=1599943 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-3e04e9fe54' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/F3LEIASEMMWKXWPVVF74A2FRTY4WAMTJ/ . Update for libpng10 addresses integer overflow, preventing denial of service via crafted PNG files in Fedora 27.. libpng10 Security Update,Fedora 27 Update,Denial Of Service Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 29, 2018 Critical Fedora
89

Fedora 23: libpng10 Critical Update - CVE-2015-8126 Buffer Overflow

The fix for CVE-8126 was incomplete in the previous 1.0.64 update.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-8c475f7169 2015-12-18 04:57:24.070371 -------------------------------------------------------------------------------- Name : libpng10 Product : Fedora 23 Version : 1.0.65 Release : 1.fc23 URL : http://www.libpng.org/pub/png/libpng.html Summary : Old version of libpng, needed to run old binaries Description : The libpng10 package contains an old version of libpng, a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. This package is needed if you want to run binaries that were linked dynamically with libpng 1.0.x. -------------------------------------------------------------------------------- Update Information: The fix for CVE-8126 was incomplete in the previous 1.0.64 update. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1281756 - CVE-2015-8126 CVE-2015-8472 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions https://bugzilla.redhat.com/show_bug.cgi?id=1281756 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libpng10' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Red Hat Security Advisory for libjpeg62 concerning CVE-9123 as a result of prior patching inadequacies, necessitating prompt attention.. Fedora Security,libpng10 Update, Buffer Overflow Fix, png Manipulation. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 18, 2015 Critical Fedora
89

Fedora 23: Essential libpng10 Security Update for DoS and Data Leak

An out-of-bounds read in png_convert_to_rfc1123() in png.c could potentially be exploited by a crafted PNG file to leak information from an application's memory (CVE-2015-7981). Buffer overflow vulnerabilities in functions png_get_PLTE/png_set_PLTE, allowing remote attackers to cause DoS to application or have unspecified other impact (CVE-2015-8126). Also includes various other. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-1d87313b7c 2015-11-24 17:51:14.496106 -------------------------------------------------------------------------------- Name : libpng10 Product : Fedora 23 Version : 1.0.64 Release : 1.fc23 URL : http://www.libpng.org/pub/png/libpng.html Summary : Old version of libpng, needed to run old binaries Description : The libpng10 package contains an old version of libpng, a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. This package is needed if you want to run binaries that were linked dynamically with libpng 1.0.x. -------------------------------------------------------------------------------- Update Information: An out-of-bounds read in png_convert_to_rfc1123() in png.c could potentially be exploited by a crafted PNG file to leak information from an application's memory (CVE-2015-7981). Buffer overflow vulnerabilities in functions png_get_PLTE/png_set_PLTE, allowing remote attackers to cause DoS to application or have unspecified other impact (CVE-2015-8126). Also includes various other small bug fixes as detailed in the package changelog. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1276416 - CVE-2015-7981 libpng: Out-of-bounds read in png_convert_to_rfc1123 https://bugzilla.redhat.com/show_bug.cgi?id=1276416 [ 2 ] Bug #1281756 - CVE-2015-8126 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions https://bugzilla.redhat.com/show_bug.cgi?id=1281756 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libpng10' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Important patch for libpng10 resolves out-of-bounds access and buffer overflow vulnerabilities, impacting users of Fedora 23.. libpng10 update, Fedora 23, security patch, information leak, buffer overflow. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 24, 2015 Critical Fedora
89

Fedora: FEDORA-2004-523 Moderate: libpng10 Security Update

Updates libpng10 to the current release 1.0.18. For details about the bugs which have been fixed in this release, see http://www.libpng.org/pub/png/libpng.html. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2004-523 2004-12-06 ---------------------------------------------------------------------Product : Fedora Core 3 Name : libpng10 Version : 1.0.18 Release : 1.fc3 Summary : Old version of libpng, needed to run old binaries. Description : The libpng10 package contains an old version of libpng, a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. This package is needed if you want to run binaries that were linked dynamically with libpng 1.0.x. ---------------------------------------------------------------------Update Information: Updates libpng10 to the current release 1.0.18. For details about the bugs which have been fixed in this release, see http://www.libpng.org/pub/png/libpng.html ---------------------------------------------------------------------* Mon Dec 06 2004 Matthias Clasen - 1.0.18-1.fc3 - Update to 1.0.18 ---------------------------------------------------------------------This update can be downloaded from: 23b47079a8e2253e052241d70046a477 SRPMS/libpng10-1.0.18-1.fc3.src.rpm 72ffed225b400ac7d34d5c5fe39eea41 x86_64/libpng10-1.0.18-1.fc3.x86_64.rpm 6da713bf028bcbe4856e2af966a8276c x86_64/libpng10-devel-1.0.18-1.fc3.x86_64.rpm a9108d62ae624d09bcada7e7694482a8 x86_64/debug/libpng10-debuginfo-1.0.18-1.fc3.x86_64.rpm cbbbe0bf08d10de030dc8c4647a4c23e x86_64/libpng10-1.0.18-1.fc3.i386.rpm cbbbe0bf08d10de030dc8c4647a4c23e i386/libpng10-1.0.18-1.fc3.i386.rpm ca82edfe095c05bda4a7e6fb30aa6305 i386/libpng10-devel-1.0.18-1.fc3.i386.rpm 600cfb8ca05af1bcb2a97c52a9a8a05e i386/debug/libpng10-debuginfo-1.0.18-1.fc3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent withthe 'up2date' command. --------------------------------------------------------------------- --fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Update to libjpeg62 version 6.2.0 in CentOS 5 brings significant improvements and critical stability adjustments.. libpng10 update, Fedora Core 3, security fixes. . LinuxSecurity.com Team

Calendar 2 Dec 09, 2004 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here