[SECURITY] Fedora Core 1 Update: libpng10-1.0.15-7

Matthias Clasen mclasen at redhat.com
Wed Aug 4 16:28:40 UTC 2004


---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-236
2004-08-04
---------------------------------------------------------------------

Product     : Fedora Core 1
Name        : libpng10
Version     : 1.0.15
Release     : 7
Summary     : Old version of libpng, needed to run old binaries.
Description :
The libpng10 package contains an old version of libpng, a library of
functions for creating and manipulating PNG (Portable Network Graphics)
image format files.

This package is needed if you want to run binaries that were linked
dynamically with libpng 1.0.x.

---------------------------------------------------------------------
Update Information:
The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

During a source code audit, Chris Evans discovered several buffer
overflows in libpng. An attacker could create a carefully crafted PNG
file in such a way that it would cause an application linked with libpng
to execute arbitrary code when the file was opened by a victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0597 to these issues. 

In addition, this audit discovered a potential NULL pointer dereference
in libpng (CAN-2004-0598) and several integer overflow issues
(CAN-2004-0599). An attacker could create a carefully crafted PNG file
in such a way that it would cause an application linked with libpng to
crash when the file was opened by the victim.

Red Hat would like to thank Chris Evans for discovering these issues.

---------------------------------------------------------------------
* Fri Jul 23 2004 Matthias Clasen <mclasen at redhat.com> 1.0.15-7

- Replace the patches for individual security problems with the
  cumulative patch issued by the png developers.
- Build for FC1

* Tue Jun 15 2004 Elliot Lee <sopwith at redhat.com>

- rebuilt

* Mon Jun 14 2004 Matthias Clasen <mclasen at redhat.com> - 1.0.15-5

- Rebuilt for FC2

* Mon Jun 14 2004 Matthias Clasen <mclasen at redhat.com> - 1.0.15-4

- Rebuilt for FC1

* Mon Jun 14 2004 Matthias Clasen <mclasen at redhat.com> - 1.0.15-3

- Reinstate and improve the transfix patch which got lost sometime ago,
  but is still needed for CAN-2002-1363 (#125934)

* Wed May 19 2004 Matthias Clasen <mclasen at redhat.com> 1.0.15-2

- Don't provide libpng-devel (#110161)

* Wed May 19 2004 Matthias Clasen <mclasen at redhat.com> 1.0.15-1

- 1.0.15
- Update rhconf2 patch
- Remove bogus badchunks patch (#89854)

* Mon May 03 2004 Matthias Clasen <mclasen at redhat.com> 1.0.13-13

- Redo the out-of-bounds fix in a slightly better way.

* Wed Apr 21 2004 Matthias Clasen <mclasen at redhat.com> 1.0.13-12

- Bump release number to disambiguate n-v-rs.

* Mon Apr 19 2004 Matthias Clasen <mclasen at redhat.com>

- fix a possible out-of-bounds read in the error message
  handler. #121229

* Tue Mar 02 2004 Elliot Lee <sopwith at redhat.com>

- rebuilt

* Fri Feb 13 2004 Elliot Lee <sopwith at redhat.com>

- rebuilt

* Mon Jun 09 2003 Elliot Lee <sopwith at redhat.com>

- This package has no epochs! remove usage thereof

* Wed Jun 04 2003 Elliot Lee <sopwith at redhat.com>

- rebuilt

* Tue Jun 03 2003 Jeff Johnson <jbj at redhat.com>

- add explicit epoch's where needed.

* Wed Jan 22 2003 Tim Powers <timp at redhat.com>

- rebuilt

* Wed Jan 15 2003 Elliot Lee <sopwith at redhat.com> 1.0.13-7

- Bump & rebuild

* Fri Dec 13 2002 Elliot Lee <sopwith at redhat.com> 1.0.13-6

- Rebuild, merging in multilib change

* Fri Jun 21 2002 Tim Powers <timp at redhat.com>

- automated rebuild

* Sun May 26 2002 Tim Powers <timp at redhat.com>

- automated rebuild

* Tue May 21 2002 Elliot Lee <sopwith at redhat.com> 1.0.13-3

- The package totally broke the backwards compatibility that it was
intended to provide.
  Fixed by setting soname to libpng.so.2, and only tweaking the build
(libpng*.{so,a}) files.
- Use _smp_mflags
- Fix rhconf patch because it was patching a symlink instead of the
actual file.
- Don't provide libpng = {version}, because then the package conflicts
with itself

* Thu May 09 2002 Jeremy Katz <katzj at redhat.com> 1.0.13-2

- rebuild

* Thu May 02 2002 Havoc Pennington <hp at redhat.com> 1.0.13-1

- upgrade to 1.0.13, plus patch tarball from libpng web site
- update rhconf patch to work with new makefiles

* Mon Mar 04 2002 Bernhard Rosenkraenzer <bero at redhat.com> 1.0.12-6

- Revert fix for #59988 as it introduces a worse problem, #60410

* Tue Feb 26 2002 Bernhard Rosenkraenzer <bero at redhat.com> 1.0.12-5

- Conflict with libpng < 1.2.0 (#59988)

* Wed Jan 30 2002 Bill Nottingham <notting at redhat.com> 1.0.12-4

- provide libpng = %{version}, libpng-devel = %{version}

* Wed Jan 09 2002 Tim Powers <timp at redhat.com>

- automated rebuild

* Fri Jan 04 2002 Bill Nottingham <notting at redhat.com> 1.0.12-2

- add devel stuff (we may change this around later)

* Wed Sep 19 2001 Bernhard Rosenkraenzer <bero at redhat.com> 1.0.12-1

- initial compat package


---------------------------------------------------------------------
This update can be downloaded from:
  http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

748a5bae718537c066affeab55f8cd13  SRPMS/libpng10-1.0.15-7.src.rpm
2a700f1c32460cd298338eb9ea8eff2f  x86_64/libpng10-1.0.15-7.x86_64.rpm
6fd56ffb02374f63a6babfce021bf726 
x86_64/libpng10-devel-1.0.15-7.x86_64.rpm
b7413234354a1bb0b0f450a55501ecf3 
x86_64/debug/libpng10-debuginfo-1.0.15-7.x86_64.rpm
76795623a70bc6724f03205acce15e63  i386/libpng10-1.0.15-7.i386.rpm
4cbe2c20bb6738d3f1a7674a413218ca  i386/libpng10-devel-1.0.15-7.i386.rpm
bfbb7f83ca69dac0aa25345ca74ad4b7 
i386/debug/libpng10-debuginfo-1.0.15-7.i386.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------







More information about the fedora-announce-list mailing list