Fix for CVE-2018-13785: the libpng10 library was vulnerable to an integer overflow and resultant divide-by-zero in the pngrutil.c:png_check_chunk_length() function. An attacker could exploit this to cause a denial of service via a crafted PNG file.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-04eded822e 2018-07-29 03:19:11.836325 --------------------------------------------------------------------------------Name : libpng10 Product : Fedora 28 Version : 1.0.69 Release : 5.fc28 URL : http://www.libpng.org/pub/png/libpng.html Summary : Old version of libpng, needed to run old binaries Description : The libpng10 package contains an old version of libpng, a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. This package is needed if you want to run binaries that were linked dynamically with libpng 1.0.x. --------------------------------------------------------------------------------Update Information: Fix for CVE-2018-13785: the libpng10 library was vulnerable to an integer overflow and resultant divide-by-zero in the pngrutil.c:png_check_chunk_length() function. An attacker could exploit this to cause a denial of service via a crafted PNG file. --------------------------------------------------------------------------------ChangeLog: * Fri Jul 13 2018 Paul Howarth - 1.0.69-5 - Fix the calculation of row_factor in png_check_chunk_length (CVE-2018-13785) * Fri Jul 13 2018 Fedora Release Engineering - 1.0.69-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1599943 - CVE-2018-13785 libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service https://bugzilla.redhat.com/show_bug.cgi?id=1599943 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-04eded822e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Fix for CVE-2018-13785: the libpng10 library was vulnerable to an integer overflow and resultant divide-by-zero in the pngrutil.c:png_check_chunk_length() function. An attacker could exploit this to cause a denial of service via a crafted PNG file.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-3e04e9fe54 2018-07-29 02:18:19.405657 --------------------------------------------------------------------------------Name : libpng10 Product : Fedora 27 Version : 1.0.69 Release : 5.fc27 URL : http://www.libpng.org/pub/png/libpng.html Summary : Old version of libpng, needed to run old binaries Description : The libpng10 package contains an old version of libpng, a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. This package is needed if you want to run binaries that were linked dynamically with libpng 1.0.x. --------------------------------------------------------------------------------Update Information: Fix for CVE-2018-13785: the libpng10 library was vulnerable to an integer overflow and resultant divide-by-zero in the pngrutil.c:png_check_chunk_length() function. An attacker could exploit this to cause a denial of service via a crafted PNG file. --------------------------------------------------------------------------------ChangeLog: * Fri Jul 13 2018 Paul Howarth - 1.0.69-5 - Fix the calculation of row_factor in png_check_chunk_length (CVE-2018-13785) * Fri Jul 13 2018 Fedora Release Engineering - 1.0.69-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Wed Feb 14 2018 Paul Howarth - 1.0.69-3 - Avoid use of arch-specific build-requires (#1545195) * Tue Feb 6 2018 Paul Howarth - 1.0.69-2 - ldconfig scriptlets replaced by RPM File Triggers from Fedora 28 - Make zlib-devel dependencies arch-specific - Preserve upstream timestamps wherepossible --------------------------------------------------------------------------------References: [ 1 ] Bug #1599943 - CVE-2018-13785 libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service https://bugzilla.redhat.com/show_bug.cgi?id=1599943 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-3e04e9fe54' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
The fix for CVE-8126 was incomplete in the previous 1.0.64 update.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-8c475f7169 2015-12-18 04:57:24.070371 -------------------------------------------------------------------------------- Name : libpng10 Product : Fedora 23 Version : 1.0.65 Release : 1.fc23 URL : http://www.libpng.org/pub/png/libpng.html Summary : Old version of libpng, needed to run old binaries Description : The libpng10 package contains an old version of libpng, a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. This package is needed if you want to run binaries that were linked dynamically with libpng 1.0.x. -------------------------------------------------------------------------------- Update Information: The fix for CVE-8126 was incomplete in the previous 1.0.64 update. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1281756 - CVE-2015-8126 CVE-2015-8472 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions https://bugzilla.redhat.com/show_bug.cgi?id=1281756 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libpng10' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
An out-of-bounds read in png_convert_to_rfc1123() in png.c could potentially be exploited by a crafted PNG file to leak information from an application's memory (CVE-2015-7981). Buffer overflow vulnerabilities in functions png_get_PLTE/png_set_PLTE, allowing remote attackers to cause DoS to application or have unspecified other impact (CVE-2015-8126). Also includes various other. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-1d87313b7c 2015-11-24 17:51:14.496106 -------------------------------------------------------------------------------- Name : libpng10 Product : Fedora 23 Version : 1.0.64 Release : 1.fc23 URL : http://www.libpng.org/pub/png/libpng.html Summary : Old version of libpng, needed to run old binaries Description : The libpng10 package contains an old version of libpng, a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. This package is needed if you want to run binaries that were linked dynamically with libpng 1.0.x. -------------------------------------------------------------------------------- Update Information: An out-of-bounds read in png_convert_to_rfc1123() in png.c could potentially be exploited by a crafted PNG file to leak information from an application's memory (CVE-2015-7981). Buffer overflow vulnerabilities in functions png_get_PLTE/png_set_PLTE, allowing remote attackers to cause DoS to application or have unspecified other impact (CVE-2015-8126). Also includes various other small bug fixes as detailed in the package changelog. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1276416 - CVE-2015-7981 libpng: Out-of-bounds read in png_convert_to_rfc1123 https://bugzilla.redhat.com/show_bug.cgi?id=1276416 [ 2 ] Bug #1281756 - CVE-2015-8126 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions https://bugzilla.redhat.com/show_bug.cgi?id=1281756 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libpng10' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Updates libpng10 to the current release 1.0.18. For details about the bugs which have been fixed in this release, see http://www.libpng.org/pub/png/libpng.html. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2004-523 2004-12-06 ---------------------------------------------------------------------Product : Fedora Core 3 Name : libpng10 Version : 1.0.18 Release : 1.fc3 Summary : Old version of libpng, needed to run old binaries. Description : The libpng10 package contains an old version of libpng, a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. This package is needed if you want to run binaries that were linked dynamically with libpng 1.0.x. ---------------------------------------------------------------------Update Information: Updates libpng10 to the current release 1.0.18. For details about the bugs which have been fixed in this release, see http://www.libpng.org/pub/png/libpng.html ---------------------------------------------------------------------* Mon Dec 06 2004 Matthias Clasen - 1.0.18-1.fc3 - Update to 1.0.18 ---------------------------------------------------------------------This update can be downloaded from: 23b47079a8e2253e052241d70046a477 SRPMS/libpng10-1.0.18-1.fc3.src.rpm 72ffed225b400ac7d34d5c5fe39eea41 x86_64/libpng10-1.0.18-1.fc3.x86_64.rpm 6da713bf028bcbe4856e2af966a8276c x86_64/libpng10-devel-1.0.18-1.fc3.x86_64.rpm a9108d62ae624d09bcada7e7694482a8 x86_64/debug/libpng10-debuginfo-1.0.18-1.fc3.x86_64.rpm cbbbe0bf08d10de030dc8c4647a4c23e x86_64/libpng10-1.0.18-1.fc3.i386.rpm cbbbe0bf08d10de030dc8c4647a4c23e i386/libpng10-1.0.18-1.fc3.i386.rpm ca82edfe095c05bda4a7e6fb30aa6305 i386/libpng10-devel-1.0.18-1.fc3.i386.rpm 600cfb8ca05af1bcb2a97c52a9a8a05e i386/debug/libpng10-debuginfo-1.0.18-1.fc3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent withthe 'up2date' command. --------------------------------------------------------------------- --fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.