Fedora Test Update Notification: libpng
Jesse Keating
jkeating at j2solutions.net
Thu Jun 17 04:07:13 UTC 2004
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- ---------------------------------------------------------------------
Fedora Test Update Notification
FEDORA-2004-1550
Bugzilla https://bugzilla.fedora.us/show_bug.cgi?id=1550
2004-06-17
- ---------------------------------------------------------------------
Name : libpng
Version 7.3 : 1.0.14-0.7x.5.legacy
Summary : A library of functions for manipulating PNG image format
files.
Description :
The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files. PNG
is a bit-mapped graphics format similar to the GIF format. PNG was
created to replace the GIF format, since GIF uses a patented data
compression algorithm.
Libpng should be installed if you need to manipulate PNG format image
files.
- ---------------------------------------------------------------------
Update Information:
CAN-2004-0421:
The Portable Network Graphics library (libpng) 1.0.15 and earlier allows
attackers to cause a denial of service (crash) via a malformed PNG image
file that triggers an error that causes an out-of-bounds read when
creating the error message.
- ---------------------------------------------------------------------
Changelog:
7.3:
* Sat May 01 2004 Seth Vidal <skvidal at phy.duke.edu> 1.0.14-0.7x.5.legacy
- - new number :)
* Sat May 01 2004 Seth Vidal <skvidal at phy.duke.edu> 1.0.14-0.7x.4.legacy.0
- - build with modified patch from rhl9 (and others) libpng update
* Thu Dec 19 2002 Jonathan Blandford <jrb at redhat.com>
- - fix security problem
- ---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedoralegacy.org/redhat/
20619750b9d6f5fb4fa4cfaad6ff31f3280372bb
7.3/updates-testing/SRPMS/libpng-1.0.14-0.7x.5.legacy.src.rpm
5a1ff70a2deb721b370bbcacff4ef3a1ee3f79ce
7.3/updates-testing/i386/libpng-1.0.14-0.7x.5.legacy.i386.rpm
Please note that this update is also available via yum and apt through
the updates-testing channel. Many people find this an easier
way to apply updates.
- ---------------------------------------------------------------------
- --
Jesse Keating RHCE (http://geek.j2solutions.net)
Fedora Legacy Team (http://www.fedoralegacy.org)
GPG Public Key (http://geek.j2solutions.net/jkeating.j2solutions.pub)
Was I helpful? Let others know:
http://svcs.affero.net/rm.php?r=jkeating
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
iD8DBQFA0Rjx4v2HLvE71NURArQ8AJ93DyuFRq1iteNJFVJ5EngOWn1c1QCfb1dF
ptDaZTeJu6JDw5hlTzPML2E=
=271+
-----END PGP SIGNATURE-----
More information about the fedora-legacy-list
mailing list