Update to 7.9.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-6b4a9c1dd1 2025-06-24 01:43:05.446986+00:00 -------------------------------------------------------------------------------- Name : optipng Product : Fedora 42 Version : 7.9.1 Release : 1.fc42 URL : https://optipng.sourceforge.net/ Summary : PNG optimizer and converter Description : OptiPNG is a PNG optimizer that recompresses image files to a smaller size, without losing any information. This program also converts external formats (BMP, GIF, PNM and TIFF) to optimized PNG, and performs PNG integrity checks and corrections. -------------------------------------------------------------------------------- Update Information: Update to 7.9.1 -------------------------------------------------------------------------------- ChangeLog: * Sun Jun 15 2025 Peter Hanecak - 7.9.1-1 - Update to 7.9.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2242460 - CVE-2023-43907 optipng: global buffer overflow via the 'buffer' variable at gifread.c. [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2242460 [ 2 ] Bug #2359202 - optipng-7.9.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2359202 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-6b4a9c1dd1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 7.9.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-0533c67535 2025-06-24 01:04:27.682929+00:00 -------------------------------------------------------------------------------- Name : optipng Product : Fedora 41 Version : 7.9.1 Release : 1.fc41 URL : Summary : PNG optimizer and converter Description : OptiPNG is a PNG optimizer that recompresses image files to a smaller size, without losing any information. This program also converts external formats (BMP, GIF, PNM and TIFF) to optimized PNG, and performs PNG integrity checks and corrections. -------------------------------------------------------------------------------- Update Information: Update to 7.9.1 -------------------------------------------------------------------------------- ChangeLog: * Sun Jun 15 2025 Peter Hanecak - 7.9.1-1 - Update to 7.9.1 * Fri Jan 17 2025 Fedora Release Engineering - 0.7.8-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2242460 - CVE-2023-43907 optipng: global buffer overflow via the 'buffer' variable at gifread.c. [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2242460 [ 2 ] Bug #2359202 - optipng-7.9.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2359202 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-0533c67535' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for optipng ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0388-1 Rating: moderate References: #1215937 Cross-References: CVE-2023-43907 CVSS scores: CVE-2023-43907 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for optipng fixes the following issues: Update to 0.7.8: * CVE-2023-43907: Fixed a global-buffer-overflow vulnerability in the GIF reader (boo#1215937). * Fixed a stack-print-after-scope defect in the error handler. * Fixed an assertion failure in the image reduction module. * Fixed the command-line wildargs expansion in the Windows port. * Refactored the structured exception handling. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2023-388=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): optipng-0.7.8-bp154.3.5.1 optipng-debuginfo-0.7.8-bp154.3.5.1 optipng-debugsource-0.7.8-bp154.3.5.1 References: https://www.suse.com/security/cve/CVE-2023-43907.html https://bugzilla.suse.com/1215937 . An update for optipng in openSUSE addresses CVE-2023-43908, identified as a low-severity vulnerability. Explore additional information.. Optipng Security Update, openSUSE Patch, Moderate Fix. . LinuxSecurity.com Team
Updated the optipng package to fix a security vulnerability (CVE-2023-43907) and other bugs. The GIF handler was vulnerable to a global buffer overflow. References: . MGASA-2023-0333 - Updated optipng packages fix a security vulnerability Publication date: 01 Dec 2023 URL: https://advisories.mageia.org/MGASA-2023-0333.html Type: security Affected Mageia releases: 8, 9 CVE: CVE-2023-43907 Updated the optipng package to fix a security vulnerability (CVE-2023-43907) and other bugs. The GIF handler was vulnerable to a global buffer overflow. References: - https://bugs.mageia.org/show_bug.cgi?id=32520 - / - - https://www.cve.org/CVERecord?id=CVE-2023-43907 SRPMS: - 9/core/optipng-0.7.8-2.mga9 - 8/core/optipng-0.7.8-2.mga8 . The latest update addresses a critical buffer overflow issue in pngquant, bolstering Debian's security for releases 10 and 11.. Bufferoverflow Fix, Mageia Security, Optipng Update. . LinuxSecurity.com Team
Update to 0.7.8 Security fix for CVE-2023-43907. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-ae05c3bca8 2023-11-14 01:55:09.715323 -------------------------------------------------------------------------------- Name : optipng Product : Fedora 38 Version : 0.7.8 Release : 1.fc38 URL : Summary : PNG optimizer and converter Description : OptiPNG is a PNG optimizer that recompresses image files to a smaller size, without losing any information. This program also converts external formats (BMP, GIF, PNM and TIFF) to optimized PNG, and performs PNG integrity checks and corrections. -------------------------------------------------------------------------------- Update Information: Update to 0.7.8 Security fix for CVE-2023-43907 -------------------------------------------------------------------------------- ChangeLog: * Sun Nov 5 2023 Peter Hanecak - 0.7.8-1 - Update to 0.7.8 * Thu Jul 20 2023 Fedora Release Engineering - 0.7.7-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2242461 - CVE-2023-43907 optipng: global buffer overflow via the 'buffer' variable at gifread.c. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2242461 [ 2 ] Bug #2247874 - optipng-0.7.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=2247874 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-ae05c3bca8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2017-1000229 and CVE-2017-16938. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-018464cbf9 2017-12-19 19:57:44.408874 --------------------------------------------------------------------------------Name : optipng Product : Fedora 26 Version : 0.7.6 Release : 6.fc26 URL : Summary : PNG optimizer and converter Description : OptiPNG is a PNG optimizer that recompresses image files to a smaller size, without losing any information. This program also converts external formats (BMP, GIF, PNM and TIFF) to optimized PNG, and performs PNG integrity checks and corrections. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-1000229 and CVE-2017-16938 --------------------------------------------------------------------------------References: [ 1 ] Bug #1520234 - CVE-2017-1000229 optipng: integer overflow in tiffread.c:minitiff_read_info() allows for arbitrary code execution https://bugzilla.redhat.com/show_bug.cgi?id=1520234 [ 2 ] Bug #1520227 - CVE-2017-16938 optipng: global buffer overflow in gifread.c:LZWReadByte when parsing malicious GIF https://bugzilla.redhat.com/show_bug.cgi?id=1520227 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade optipng' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Two vulnerabilities were discovered in optipng, an advanced PNG optimizer, which may result in denial of service or the execution of arbitrary code if a malformed file is processed. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4058-1
optipng, an advanced PNG (Portable Network Graphics) optimizer, has been found vulnerable to a buffer overflow which allows remote attackers to cause a denial-of-service attack or other unspecified impact with a maliciously crafted GIF format file, related to an . Package : optipng Version : 0.6.4-1+deb7u4 CVE ID : CVE-2017-16938 Debian Bug : 878839 optipng, an advanced PNG (Portable Network Graphics) optimizer, has been found vulnerable to a buffer overflow which allows remote attackers to cause a denial-of-service attack or other unspecified impact with a maliciously crafted GIF format file, related to an uncontrolled loop in the LZWReadByte function of the gifread.c file. For Debian 7 "Wheezy", these problems have been fixed in version 0.6.4-1+deb7u4. We recommend that you upgrade your optipng packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Update libpng to address serious security vulnerability impacting Ubuntu 14.04 Trusty and mitigate risks of system crashes.. optipng Security, Buffer Overflow Fix, Denial Of Service, Image Optimization Update, Debian Security Advisory. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.