Login
Login-Name Passwort


 
Newsletter
Werbung

Sicherheit: Mehrere Probleme in libpng
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in libpng
ID: FEDORA-2015-39499d9af8
Distribution: Fedora
Plattformen: Fedora 23
Datum: So, 3. Januar 2016, 12:55
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8540
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7981
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8472
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8126

Originalnachricht

Name        : libpng12
Product : Fedora 23
Version : 1.2.56
Release : 1.fc23
URL : http://www.libpng.org/pub/png/
Summary : Old version of libpng, needed to run old binaries
Description :
The libpng12 package provides libpng 1.2, an older version of the libpng
library for manipulating PNG (Portable Network Graphics) image format files.
This version should be used only if you are unable to use the current
version of libpng.

-------------------------------------------------------------------------------
-
Update Information:

Latest upstream release, includes fixes for security vulnerabilities:
CVE-2015-7981, CVE-2015-8126, CVE-2015-8540
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #1276416 - CVE-2015-7981 libpng: Out-of-bounds read in
png_convert_to_rfc1123
https://bugzilla.redhat.com/show_bug.cgi?id=1276416
[ 2 ] Bug #1281756 - CVE-2015-8126 CVE-2015-8472 libpng: Buffer overflow
vulnerabilities in png_get_PLTE/png_set_PLTE functions
https://bugzilla.redhat.com/show_bug.cgi?id=1281756
[ 3 ] Bug #1291312 - CVE-2015-8540 libpng: underflow read in
png_check_keyword()
https://bugzilla.redhat.com/show_bug.cgi?id=1291312
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update libpng12' at the command line.
For more information, refer to "Managing Software with yum",
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung