[SECURITY] Fedora Core 1 Update: libpng10-1.0.15-4

Matthias Clasen mclasen at redhat.com
Fri Jun 18 17:27:52 UTC 2004


---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-174
2004-06-18
---------------------------------------------------------------------
 
Product     : Fedora Core 1
Name        : libpng10
Version     : 1.0.15
Release     : 4
Summary     : Old version of libpng, needed to run old binaries.
Description :
The libpng10 package contains an old version of libpng, a library of
functions for creating and manipulating PNG (Portable Network Graphics)
image format files.
 
This package is needed if you want to run binaries that were linked
dynamically
with libpng 1.0.x.
 
---------------------------------------------------------------------
Update Information:
 
During an audit of Red Hat Linux updates, the Fedora Legacy team found a
security issue in libpng that had not been fixed in Fedora Core. An
attacker could carefully craft a PNG file in such a way that
it would cause an application linked to libpng to crash or potentially
execute arbitrary code when opened by a victim.
 
---------------------------------------------------------------------
 
---------------------------------------------------------------------
This update can be downloaded from:
  http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
 
27291030c4b45837604fa29ea1ba63af  SRPMS/libpng10-1.0.15-4.src.rpm
373999494fd66d5110f30cc13f23afdf  x86_64/libpng10-1.0.15-4.x86_64.rpm
c3179356daded13a6f03f5384e201772 
x86_64/libpng10-devel-1.0.15-4.x86_64.rpm
0583f6e917579a841183ade07772ee71 
x86_64/debug/libpng10-debuginfo-1.0.15-4.x86_64.rpm
c340858b643a92beb4ab16bcfff55e6c  i386/libpng10-1.0.15-4.i386.rpm
4642cf8bafa073269763964a85ef5139  i386/libpng10-devel-1.0.15-4.i386.rpm
67b64172374624083b436c49d0ae7a8a 
i386/debug/libpng10-debuginfo-1.0.15-4.i386.rpm
 
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------





More information about the fedora-announce-list mailing list