FSA/F7/FEDORA-2007-0004

[SECURITY] Fedora 7 Update: libpng10-1.0.26-1.fc7.1
Fedora Update Notification FEDORA-2007-0004 (Corrected) None

Name       : libpng10 Product    : Fedora 7 Version    : 1.0.26 Release    : 1.fc7.1 Summary    : Old version of libpng, needed to run old binaries Description : The libpng10 package contains an old version of libpng, a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files.

This package is needed if you want to run binaries that were linked dynamically with libpng 1.0.x.

Update Information:

The png_handle_tRNS function in pngrutil.c in libpng before 1.0.25 and 1.2.x before 1.2.17 allows remote attackers to cause a denial of service (application crash) via a grayscale PNG image with a bad tRNS chunk CRC value.

This update to libpng 1.0.26 resolves this problem.

ChangeLog:

- update to 1.0.26 to address DoS issue (#240398, CVE-2007-2445) - update soname patch - libpng.txt now has a versioned filename
 * Sun May 20 2007 Paul Howarth  1.0.26-1

References:

Bug #240398 - https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=240398 CVE-2007-2445 - http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2445

Updated packages:

e9d0f41b57d69f1e6586e0b503ef9b6ccc3e5e9a libpng10-devel-1.0.26-1.fc7.1.ppc64.rpm 2ef256533015c24e8f118d522545ed18a8643ed9 libpng10-1.0.26-1.fc7.1.ppc64.rpm 35238b6de27fb1400b6843fb26dd6d4acc27cc33 libpng10-debuginfo-1.0.26-1.fc7.1.ppc64.rpm 0a3e2caac921bdd85bca761ee19cd17172e130b0 libpng10-1.0.26-1.fc7.1.i386.rpm 58be28d63413aff84fcf3e36ffeb8884e751cca8 libpng10-devel-1.0.26-1.fc7.1.i386.rpm 6b9e214bf674647fa3ccd46983d82c000f822708 libpng10-debuginfo-1.0.26-1.fc7.1.i386.rpm 35f6ec7b1b873d8c303ca519b60d68fda09b08c9 libpng10-1.0.26-1.fc7.1.x86_64.rpm c0a5ee9564b9c3aaf59aa5c55f0532c3484e0b05 libpng10-devel-1.0.26-1.fc7.1.x86_64.rpm 27f21433ba444324e108340c79b41952358e7a5d libpng10-debuginfo-1.0.26-1.fc7.1.x86_64.rpm 925fde948bb53bb0c7bd531bb954ad85a925c941 libpng10-1.0.26-1.fc7.1.ppc.rpm a9d7f273e7adff68cc418b68d6c666574deaef8b libpng10-debuginfo-1.0.26-1.fc7.1.ppc.rpm 5896b5ca2aba2dee876323315f56fc3057079c76 libpng10-devel-1.0.26-1.fc7.1.ppc.rpm d10cc045eb953333e8b60bb54984b815b0c088ec libpng10-1.0.26-1.fc7.1.src.rpm

This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at http://docs.fedoraproject.org/yum/.