You are here
Home > Preporuke > Sigurnosni nedostatak programske biblioteke libpng10

Sigurnosni nedostatak programske biblioteke libpng10

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2016-1a7e14d084
2017-01-07 17:58:43.233166
——————————————————————————–

Name : libpng10
Product : Fedora 24
Version : 1.0.67
Release : 1.fc24
URL : http://www.libpng.org/pub/png/libpng.html
Summary : Old version of libpng, needed to run old binaries
Description :
The libpng10 package contains an old version of libpng, a library of functions
for creating and manipulating PNG (Portable Network Graphics) image format
files.

This package is needed if you want to run binaries that were linked dynamically
with libpng 1.0.x.

——————————————————————————–
Update Information:

This update fixes an old NULL pointer dereference bug in png_set_text_2()
discovered and patched by Patrick Keshishian (CVE-2016-10087). The potential
“NULL dereference” bug has existed in libpng since version 0.71 of June 26,
1995. To be vulnerable, an application has to load a text chunk into the png
structure, then delete all text, then add another text chunk to the same png
structure, which seems to be an unlikely sequence, but it has happened. The
update also fixes some documentation typos and an instance of undefined
behavior.
——————————————————————————–
References:

[ 1 ] Bug #1409617 – CVE-2016-10087 libpng: NULL pointer dereference in png_set_text_2()
https://bugzilla.redhat.com/show_bug.cgi?id=1409617
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade libpng10’ at the command line.
For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

——————————————————————————–
Fedora Update Notification
FEDORA-2016-a4b06a036b
2017-01-07 17:59:35.684017
——————————————————————————–

Name : libpng10
Product : Fedora 25
Version : 1.0.67
Release : 1.fc25
URL : http://www.libpng.org/pub/png/libpng.html
Summary : Old version of libpng, needed to run old binaries
Description :
The libpng10 package contains an old version of libpng, a library of functions
for creating and manipulating PNG (Portable Network Graphics) image format
files.

This package is needed if you want to run binaries that were linked dynamically
with libpng 1.0.x.

——————————————————————————–
Update Information:

This update fixes an old NULL pointer dereference bug in png_set_text_2()
discovered and patched by Patrick Keshishian (CVE-2016-10087). The potential
“NULL dereference” bug has existed in libpng since version 0.71 of June 26,
1995. To be vulnerable, an application has to load a text chunk into the png
structure, then delete all text, then add another text chunk to the same png
structure, which seems to be an unlikely sequence, but it has happened. The
update also fixes some documentation typos and an instance of undefined
behavior.
——————————————————————————–
References:

[ 1 ] Bug #1409617 – CVE-2016-10087 libpng: NULL pointer dereference in png_set_text_2()
https://bugzilla.redhat.com/show_bug.cgi?id=1409617
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade libpng10’ at the command line.
For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

AutorVlatka Misic
Cert idNCERT-REF-2017-01-0070-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa openssh

Otkriveni su sigurnosni nedostaci u programskom paketu openssh za operacijski sustav Fedora. Otkriveni nedostaci potencijalnim napadačima omogućuju izvršavanje proizvoljnih PKCS#11...

Close