U radu programskih paketa libpng i libpng10 uočeno je više sigurnosnih propusta koje udaljeni napadač može iskoristiti za napad uskraćivanjem usluga (DoS) te izmjenu proizvoljnih podataka.
Paket: | libpng 1.x, libpng10 1.x |
Operacijski sustavi: | Fedora 15, Fedora 16, Fedora 17 |
Kritičnost: | 6.5 |
Problem: | cjelobrojno prepisivanje, pogreška u programskoj funkciji |
Iskorištavanje: | udaljeno |
Posljedica: | izmjena podataka, uskraćivanje usluga (DoS) |
Rješenje: | programska zakrpa proizvođača |
CVE: | CVE-2011-3026, CVE-2011-2501, CVE-2004-0421, CVE-2011-2691, CVE-2011-2690, CVE-2011-2692 |
Izvorni ID preporuke: | FEDORA-2012-2028 |
Izvor: | Fedora |
Problem: | |
Sigurnosne ranjivosti se javljaju zbog pogrešaka u funkcijama "png_format_buffer" i "png_err", preljeva međuspremnika prilikom pozivanja funkcije "png_rgb_to_gray", itd. |
|
Posljedica: | |
Udaljeni napadač navedene ranjivosti može iskoristiti za izmjenu proizvoljnih podataka te DoS (eng. Denial of Service) napad. |
|
Rješenje: | |
Svim se korisnicima navedenog programskog paketa, u svrhu zaštite sigurnosti, savjetuje njegova nadogradnja na novije inačice. |
Izvorni tekst preporuke
-------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-2028
2012-02-19 23:01:48
--------------------------------------------------------------------------------
Name : libpng10
Product : Fedora 16
Version : 1.0.57
Release : 1.fc16
URL : http://www.libpng.org/pub/png/libpng.html
Summary : Old version of libpng, needed to run old binaries
Description :
The libpng10 package contains an old version of libpng, a library of functions
for creating and manipulating PNG (Portable Network Graphics) image format
files.
This package is needed if you want to run binaries that were linked dynamically
with libpng 1.0.x.
--------------------------------------------------------------------------------
Update Information:
This update addresses an integer overflow in the libpng10 PNG library, which
could lead to the execution of arbitrary code if a malformed image is processed.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Feb 19 2012 Paul Howarth <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 1.0.57-1
- update to 1.0.57 (fixed CVE-2011-3026 buffer overrun bug)
* Thu Jan 5 2012 Paul Howarth <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 1.0.56-2
- rebuilt for gcc 4.7
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #790737 - CVE-2011-3026 libpng: Heap-buffer-overflow in
png_decompress_chunk (MFSA 2012-11)
https://bugzilla.redhat.com/show_bug.cgi?id=790737
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update libpng10' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-2003
2012-02-19 17:14:07
--------------------------------------------------------------------------------
Name : libpng10
Product : Fedora 17
Version : 1.0.57
Release : 1.fc17
URL : http://www.libpng.org/pub/png/libpng.html
Summary : Old version of libpng, needed to run old binaries
Description :
The libpng10 package contains an old version of libpng, a library of functions
for creating and manipulating PNG (Portable Network Graphics) image format
files.
This package is needed if you want to run binaries that were linked dynamically
with libpng 1.0.x.
--------------------------------------------------------------------------------
Update Information:
This update addresses an integer overflow in the libpng10 PNG library, which
could lead to the execution of arbitrary code if a malformed image is processed.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #790737 - CVE-2011-3026 libpng: Heap-buffer-overflow in
png_decompress_chunk (MFSA 2012-11)
https://bugzilla.redhat.com/show_bug.cgi?id=790737
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update libpng10' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-1892
2012-02-17 03:56:38
--------------------------------------------------------------------------------
Name : libpng
Product : Fedora 17
Version : 1.5.8
Release : 2.fc17
URL : http://www.libpng.org/pub/png/
Summary : A library of functions for manipulating PNG image format files
Description :
The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files. PNG
is a bit-mapped graphics format similar to the GIF format. PNG was
created to replace the GIF format, since GIF uses a patented data
compression algorithm.
Libpng should be installed if you need to manipulate PNG format image
files.
--------------------------------------------------------------------------------
Update Information:
Fix nasty buffer overrun bug, CVE-2011-3026
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #790737 - CVE-2011-3026 libpng: Heap-buffer-overflow in
png_decompress_chunk (MFSA 2012-11)
https://bugzilla.redhat.com/show_bug.cgi?id=790737
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update libpng' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-2008
2012-02-19 23:00:43
--------------------------------------------------------------------------------
Name : libpng10
Product : Fedora 15
Version : 1.0.57
Release : 1.fc15
URL : http://www.libpng.org/pub/png/libpng.html
Summary : Old version of libpng, needed to run old binaries
Description :
The libpng10 package contains an old version of libpng, a library of functions
for creating and manipulating PNG (Portable Network Graphics) image format
files.
This package is needed if you want to run binaries that were linked dynamically
with libpng 1.0.x.
--------------------------------------------------------------------------------
Update Information:
This update addresses an integer overflow in the libpng10 PNG library, which
could lead to the execution of arbitrary code if a malformed image is processed.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Feb 19 2012 Paul Howarth <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 1.0.57-1
- update to 1.0.57 (fixed CVE-2011-3026 buffer overrun bug)
* Thu Jan 5 2012 Paul Howarth <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 1.0.56-2
- rebuilt for gcc 4.7
* Sat Jul 9 2011 Paul Howarth <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 1.0.56-1
- update to 1.0.56
- fix regression in Makefile.am/Makefile.in
- fix "make distcheck"
- drop upstreamed fix for libpng.sym build failure
* Thu Jul 7 2011 Paul Howarth <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 1.0.55-1
- update to 1.0.55
- fixed uninitialized memory read in png_format_buffer()
(CVE-2011-2501, related to CVE-2004-0421)
- pass "" instead of '�' to png_default_error() in png_err() (CVE-2011-2691)
- check for up->location !PNG_AFTER_IDAT when writing unknown chunks before
IDAT
- ported bugfix in pngrtran.c from 1.5.3: when expanding a paletted image,
always expand to RGBA if transparency is present
- check for integer overflow in png_set_rgb_to_gray() (CVE-2011-2690)
- check for sCAL chunk too short (CVE-2011-2692)
- drop upstreamed patch for CVE-2011-2501
- add patch to fix build failure due to regression in libpng.sym creation
* Wed Jun 29 2011 Paul Howarth <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 1.0.54-3
- fix 1-byte uninitialized memory reference in png_format_buffer()
(CVE-2011-2501, related to CVE-2004-0421)
- nobody else likes macros for commands
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #790737 - CVE-2011-3026 libpng: Heap-buffer-overflow in
png_decompress_chunk (MFSA 2012-11)
https://bugzilla.redhat.com/show_bug.cgi?id=790737
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update libpng10' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-1930
2012-02-17 23:22:27
--------------------------------------------------------------------------------
Name : libpng
Product : Fedora 15
Version : 1.2.46
Release : 2.fc15
URL : http://www.libpng.org/pub/png/
Summary : A library of functions for manipulating PNG image format files
Description :
The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files. PNG
is a bit-mapped graphics format similar to the GIF format. PNG was
created to replace the GIF format, since GIF uses a patented data
compression algorithm.
Libpng should be installed if you need to manipulate PNG format image
files.
--------------------------------------------------------------------------------
Update Information:
Fix nasty buffer overrun bug, CVE-2011-3026
--------------------------------------------------------------------------------
ChangeLog:
* Thu Feb 16 2012 Tom Lane <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 2:1.2.46-2
- Fix CVE-2011-3026
Resolves: #791183
* Thu Jul 14 2011 Tom Lane <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 2:1.2.46-1
- Update to libpng 1.2.46, includes fixes for CVE-2011-2501, CVE-2011-2690,
CVE-2011-2691, CVE-2011-2692
Resolves: #717509
Resolves: #721307
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #790737 - CVE-2011-3026 libpng: Heap-buffer-overflow in
png_decompress_chunk (MFSA 2012-11)
https://bugzilla.redhat.com/show_bug.cgi?id=790737
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update libpng' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke