-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2010-10833 2010-07-06 16:25:03 --------------------------------------------------------------------------------
Name : libpng10 Product : Fedora 12 Version : 1.0.54 Release : 1.fc12 URL : http://www.libpng.org/pub/png/libpng.html Summary : Old version of libpng, needed to run old binaries Description : The libpng10 package contains an old version of libpng, a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. This package is needed if you want to run binaries that were linked dynamically with libpng 1.0.x. -------------------------------------------------------------------------------- Update Information: This update addresses two security issues: * CVE-2010-1205, in which a buffer overflow might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row. * CVE-2010-2249, in which a memory leak allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks. -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 2 2010 Paul Howarth <[email protected]> 1.0.54-1 - update to 1.0.54 - fixes CVE-2010-1205 (out-of-bounds write to memory) - fixes CVE-2010-2249 (memory leak with images having malformed sCAL chunks) * Thu Feb 25 2010 Paul Howarth <[email protected]> 1.0.53-1 - update to 1.0.53 - fixes CVE-2010-0205 (libpng stalls on highly compressed ancillary chunks) - drop patch for #555485, included upstream * Thu Jan 7 2010 Paul Howarth <[email protected]> 1.0.52-2 - add upstream fix reinstating PNG_READ_16_TO_8_SUPPORTED and PNG_READ_GRAY_TO_RGB_SUPPORTED (not defined in 1.0.51 and 1.0.52), causing API/ABI regressions (#555485) * Mon Jan 4 2010 Paul Howarth <[email protected]> 1.0.52-1 - update to 1.0.52 (minor changes, see ANNOUNCE for details) * Thu Dec 3 2009 Paul Howarth <[email protected]> 1.0.51-1 - update to 1.0.51 (see ANNOUNCE for details) - update soname patch to apply to 1.0.51 -------------------------------------------------------------------------------- References: [ 1 ] Bug #608238 - CVE-2010-1205 libpng: out-of-bounds memory write https://bugzilla.redhat.com/show_bug.cgi?id=608238 [ 2 ] Bug #608644 - CVE-2010-2249 libpng: Memory leak when processing Physical Scale (sCAL) images https://bugzilla.redhat.com/show_bug.cgi?id=608644 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libpng10' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list [email protected] https://admin.fedoraproject.org/mailman/listinfo/package-announce
