[CLA-2003:564] Conectiva Linux Security Announcement - libpng

From: secureat_private
Date: Thu Jan 23 2003 - 12:22:27 PST

  • Next message: Steven M. Christey: "RE: [Full-Disclosure] Re: New Web Vulnerability - Cross-Site Tracing"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - --------------------------------------------------------------------------
    CONECTIVA LINUX SECURITY ANNOUNCEMENT 
    - --------------------------------------------------------------------------
    
    PACKAGE   : libpng
    SUMMARY   : Buffer overflow vulnerability
    DATE      : 2003-01-23 18:17:00
    ID        : CLA-2003:564
    RELEVANT
    RELEASES  : 6.0, 7.0, 8
    
    - -------------------------------------------------------------------------
    
    DESCRIPTION
     libpng is a library used to create and manipulate PNG (Portable
     Network Graphics) image files. 
     
     Glenn Randers-Pehrson discovered a buffer overflow vulnerability in
     unpatched libpng versions prior to 1.0.15 and 1.2.5(*) (inclusive).
     
     Programs such as web browsers and various others common applications
     make use of libpng. An attacker could exploit this vulnerability to
     remotely run arbitrary code or crash such applications by using a
     specially crafted png image.
     
     This update provides patched versions of libpng with fixes for this
     vulnerability.
     
     * The libpng-1.2.X series is available only in Conectiva Linux 8 in
     the libpng3 package.
    
    
    SOLUTION
     All users should upgrade.
     
     Please note that in order to complete the upgrade process, you must
     restart all running aplications that are linked against libpng after
     the new packages installation. You can see a list of such
     applications using the lsof utility, as seen below:
     
     # lsof | grep libpng
     
     
     REFERENCES:
     1.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-1363
    
    
    UPDATED PACKAGES
    ftp://atualizacoes.conectiva.com.br/6.0/RPMS/libpng-1.0.14-1U60_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/6.0/RPMS/libpng-devel-1.0.14-1U60_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/6.0/SRPMS/libpng-1.0.14-1U60_2cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/7.0/RPMS/libpng-1.0.14-1U70_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/7.0/RPMS/libpng-devel-1.0.14-1U70_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/7.0/RPMS/libpng-devel-static-1.0.14-1U70_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/7.0/RPMS/libpng-doc-1.0.14-1U70_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/7.0/SRPMS/libpng-1.0.14-1U70_2cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/libpng-1.0.14-1U80_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/libpng3-1.2.4-1U80_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/libpng-devel-1.2.4-1U80_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/libpng-devel-static-1.2.4-1U80_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/libpng-doc-1.2.4-1U80_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/SRPMS/libpng-1.0.14-1U80_2cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/8/SRPMS/libpng3-1.2.4-1U80_2cl.src.rpm
    
    
    ADDITIONAL INSTRUCTIONS
     Users of Conectiva Linux version 6.0 or higher may use apt to perform 
     upgrades of RPM packages:
    
     - run:                 apt-get update
     - after that, execute: apt-get upgrade
    
     Detailed instructions reagarding the use of apt and upgrade examples 
     can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en
    
    
    - -------------------------------------------------------------------------
    All packages are signed with Conectiva's GPG key. The key and instructions
    on how to import it can be found at 
    http://distro.conectiva.com.br/seguranca/chave/?idioma=en
    Instructions on how to check the signatures of the RPM packages can be
    found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en
    - -------------------------------------------------------------------------
    All our advisories and generic update instructions can be viewed at
    http://distro.conectiva.com.br/atualizacoes/?idioma=en
    
    - -------------------------------------------------------------------------
    subscribe: conectiva-updates-subscribeat_private
    unsubscribe: conectiva-updates-unsubscribeat_private
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.6 (GNU/Linux)
    Comment: For info see http://www.gnupg.org
    
    iD8DBQE+ME8C42jd0JmAcZARAutcAJ4l1r8+4DQMhITqKRG+4OKlf6S6rACeKeDp
    UCBZjAFf6uxVlu+g6Yarj78=
    =9Yh6
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Thu Jan 23 2003 - 16:45:36 PST