[SECURITY] Fedora 7 Update: libpng10-1.0.26-1.fc7.1

updates at fedoraproject.org updates at fedoraproject.org
Thu May 31 18:07:50 UTC 2007


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2007-0001
None
--------------------------------------------------------------------------------

Name        : libpng10
Product     : Fedora 7
Version     : 1.0.26
Release     : 1.fc7.1
Summary     : Old version of libpng, needed to run old binaries
Description :
The libpng10 package contains an old version of libpng, a library of functions
for creating and manipulating PNG (Portable Network Graphics) image format
files.

This package is needed if you want to run binaries that were linked dynamically
with libpng 1.0.x.

--------------------------------------------------------------------------------
Update Information:

The png_handle_tRNS function in pngrutil.c in libpng before 1.0.25 and 1.2.x before 1.2.17 allows remote attackers to cause a denial of service (application crash) via a grayscale PNG image with a bad tRNS chunk CRC value.

This update to libpng 1.0.26 resolves this problem.
--------------------------------------------------------------------------------
ChangeLog:

* Sun May 20 2007 Paul Howarth <paul at city-fan.org> 1.0.26-1
- update to 1.0.26 to address DoS issue (#240398, CVE-2007-2445)
- update soname patch
- libpng.txt now has a versioned filename
--------------------------------------------------------------------------------
References:

  Bug #240398 - https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=240398
  CVE-2007-2445 - http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2445
--------------------------------------------------------------------------------
Updated packages:

e9d0f41b57d69f1e6586e0b503ef9b6ccc3e5e9a libpng10-devel-1.0.26-1.fc7.1.ppc64.rpm
2ef256533015c24e8f118d522545ed18a8643ed9 libpng10-1.0.26-1.fc7.1.ppc64.rpm
35238b6de27fb1400b6843fb26dd6d4acc27cc33 libpng10-debuginfo-1.0.26-1.fc7.1.ppc64.rpm
0a3e2caac921bdd85bca761ee19cd17172e130b0 libpng10-1.0.26-1.fc7.1.i386.rpm
58be28d63413aff84fcf3e36ffeb8884e751cca8 libpng10-devel-1.0.26-1.fc7.1.i386.rpm
6b9e214bf674647fa3ccd46983d82c000f822708 libpng10-debuginfo-1.0.26-1.fc7.1.i386.rpm
35f6ec7b1b873d8c303ca519b60d68fda09b08c9 libpng10-1.0.26-1.fc7.1.x86_64.rpm
c0a5ee9564b9c3aaf59aa5c55f0532c3484e0b05 libpng10-devel-1.0.26-1.fc7.1.x86_64.rpm
27f21433ba444324e108340c79b41952358e7a5d libpng10-debuginfo-1.0.26-1.fc7.1.x86_64.rpm
925fde948bb53bb0c7bd531bb954ad85a925c941 libpng10-1.0.26-1.fc7.1.ppc.rpm
a9d7f273e7adff68cc418b68d6c666574deaef8b libpng10-debuginfo-1.0.26-1.fc7.1.ppc.rpm
5896b5ca2aba2dee876323315f56fc3057079c76 libpng10-devel-1.0.26-1.fc7.1.ppc.rpm
d10cc045eb953333e8b60bb54984b815b0c088ec libpng10-1.0.26-1.fc7.1.src.rpm

This update can be installed with the 'yum' update program.  Use 'yum update
package-name' at the command line.  For more information, refer to 'Managing
Software with yum,' available at http://docs.fedoraproject.org/yum/.
--------------------------------------------------------------------------------




More information about the Fedora-package-announce mailing list