Date:         Wed, 31 Oct 2007 15:17:12 -0500
Reply-To:     Troy Dawson 
Sender:       Security Errata for Scientific Linux
              
From:         Troy Dawson 
Subject:      Security ERRATA for libpng on SL5.x, SL4.x i386/x86_64
Comments: To: scientific-linux-errata@fnal.gov

Synopsis:    Moderate: libpng security update
Issue date:    2007-10-23
CVE Names:    CVE-2007-5269

Several flaws were discovered in the way libpng handled various PNG image
chunks.  An attacker could create a carefully crafted PNG image file in
such a way that it could cause an application linked with libpng to crash
when the file was manipulated. (CVE-2007-5269)

SL 4.x

   SRPMS:
libpng10-1.0.16-3.1.src.rpm
   i386:
libpng10-1.0.16-3.1.i386.rpm
libpng10-devel-1.0.16-3.1.i386.rpm
libpng-1.2.7-3.1.i386.rpm
libpng-devel-1.2.7-3.1.i386.rpm
   x86_64:
libpng10-1.0.16-3.1.i386.rpm
libpng10-1.0.16-3.1.x86_64.rpm
libpng10-devel-1.0.16-3.1.x86_64.rpm
libpng-1.2.7-3.1.i386.rpm
libpng-1.2.7-3.1.x86_64.rpm
libpng-devel-1.2.7-3.1.x86_64.rpm

SL 5.x

   SRPMS:
libpng-1.2.10-7.1.el5.1.src.rpm
   i386:
libpng-1.2.10-7.1.el5.1.i386.rpm
libpng-devel-1.2.10-7.1.el5.1.i386.rpm
   x86_64:
libpng-1.2.10-7.1.el5.1.i386.rpm
libpng-1.2.10-7.1.el5.1.x86_64.rpm
libpng-devel-1.2.10-7.1.el5.1.i386.rpm
libpng-devel-1.2.10-7.1.el5.1.x86_64.rpm

-Connie Sieh
-Troy Dawson
lastline

SciLinux: CVE-2007-5269 libpng SL5.x, SL4.x i386/x86_64

Moderate: libpng security update

Summary

Date:         Wed, 31 Oct 2007 15:17:12 -0500Reply-To:     Troy Dawson Sender:       Security Errata for Scientific Linux              From:         Troy Dawson Subject:      Security ERRATA for libpng on SL5.x, SL4.x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis:    Moderate: libpng security updateIssue date:    2007-10-23CVE Names:    CVE-2007-5269Several flaws were discovered in the way libpng handled various PNG imagechunks.  An attacker could create a carefully crafted PNG image file insuch a way that it could cause an application linked with libpng to crashwhen the file was manipulated. (CVE-2007-5269)SL 4.x   SRPMS:libpng10-1.0.16-3.1.src.rpm   i386:libpng10-1.0.16-3.1.i386.rpmlibpng10-devel-1.0.16-3.1.i386.rpmlibpng-1.2.7-3.1.i386.rpmlibpng-devel-1.2.7-3.1.i386.rpm   x86_64:libpng10-1.0.16-3.1.i386.rpmlibpng10-1.0.16-3.1.x86_64.rpmlibpng10-devel-1.0.16-3.1.x86_64.rpmlibpng-1.2.7-3.1.i386.rpmlibpng-1.2.7-3.1.x86_64.rpmlibpng-devel-1.2.7-3.1.x86_64.rpmSL 5.x   SRPMS:libpng-1.2.10-7.1.el5.1.src.rpm   i386:libpng-1.2.10-7.1.el5.1.i386.rpmlibpng-devel-1.2.10-7.1.el5.1.i386.rpm   x86_64:libpng-1.2.10-7.1.el5.1.i386.rpmlibpng-1.2.10-7.1.el5.1.x86_64.rpmlibpng-devel-1.2.10-7.1.el5.1.i386.rpmlibpng-devel-1.2.10-7.1.el5.1.x86_64.rpm-Connie Sieh-Troy Dawsonlastline



Security Fixes

Severity

Related News