Skip to navigation

Security Advisory libpng security update

Advisory: RHSA-2004:249-07
Type: Security Advisory
Severity: Important
Issued on: 2004-06-18
Last updated on: 2004-06-18
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 3)
CVEs (cve.mitre.org): CVE-2002-1363

Details

Updated libpng packages that fix a possible buffer overflow are now available.

The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

During an audit of Red Hat Linux updates, the Fedora Legacy team found a
security issue in libpng that had not been fixed in Red Hat Enterprise
Linux 3. An attacker could carefully craft a PNG file in such a way that
it would cause an application linked to libpng to crash or potentially
execute arbitrary code when opened by a victim.

Note: this issue does not affect Red Hat Enterprise Linux 2.1

Users are advised to upgrade to these updated packages that contain a
backported security fix and are not vulnerable to this issue.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

If up2date fails to connect to Red Hat Network due to SSL
Certificate Errors, you need to install a version of the
up2date client with an updated certificate. The latest version of
up2date is available from the Red Hat FTP site and may also be
downloaded directly from the RHN website:

https://rhn.redhat.com/help/latest-up2date.pxt

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
libpng-1.2.2-24.src.rpm
File outdated by:  RHSA-2010:0534
    MD5: 955bd34890b25d65120f30250a75d2fb
libpng-1.2.2-24.src.rpm
File outdated by:  RHSA-2010:0534
    MD5: 955bd34890b25d65120f30250a75d2fb
libpng10-1.0.13-14.src.rpm
File outdated by:  RHSA-2010:0534
    MD5: 4959b14e2264df985dacfac43e24df40
libpng10-1.0.13-14.src.rpm
File outdated by:  RHSA-2010:0534
    MD5: 4959b14e2264df985dacfac43e24df40
 
IA-32:
libpng-1.2.2-24.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: af63ef937508fd3bc25bb54203e9d9da
libpng-devel-1.2.2-24.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: 80f1c12114bf5648ccf56c270a3dcd5e
libpng10-1.0.13-14.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: 645136e04ec539eabf6c9f8106f62f47
libpng10-devel-1.0.13-14.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: d42c29c9604d0b2db4af78f5875bb468
 
x86_64:
libpng-1.2.2-24.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: af63ef937508fd3bc25bb54203e9d9da
libpng-1.2.2-24.x86_64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 56f6e9b47b537fe124b9ed874c379bcc
libpng-devel-1.2.2-24.x86_64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 36c04c69972678f7279991cbf49763ad
libpng10-1.0.13-14.x86_64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 8b12075058f65c087e97f88f9d63e027
libpng10-devel-1.0.13-14.x86_64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 14dd5f536db290d29895252af5a38b5e
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
libpng-1.2.2-24.src.rpm
File outdated by:  RHSA-2010:0534
    MD5: 955bd34890b25d65120f30250a75d2fb
libpng-1.2.2-24.src.rpm
File outdated by:  RHSA-2010:0534
    MD5: 955bd34890b25d65120f30250a75d2fb
libpng10-1.0.13-14.src.rpm
File outdated by:  RHSA-2010:0534
    MD5: 4959b14e2264df985dacfac43e24df40
libpng10-1.0.13-14.src.rpm
File outdated by:  RHSA-2010:0534
    MD5: 4959b14e2264df985dacfac43e24df40
 
IA-32:
libpng-1.2.2-24.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: af63ef937508fd3bc25bb54203e9d9da
libpng-devel-1.2.2-24.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: 80f1c12114bf5648ccf56c270a3dcd5e
libpng10-1.0.13-14.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: 645136e04ec539eabf6c9f8106f62f47
libpng10-devel-1.0.13-14.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: d42c29c9604d0b2db4af78f5875bb468
 
IA-64:
libpng-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 4c046aafa3cc058427ca2ffe3df4374c
libpng-devel-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2010:0534
    MD5: cd5181aeae289c6446d4458071c18d2c
libpng10-1.0.13-14.ia64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 5168760faafc399c90958c60412ce516
libpng10-devel-1.0.13-14.ia64.rpm
File outdated by:  RHSA-2010:0534
    MD5: fe4a1b47268982804c2068ba6158c8d2
 
PPC:
libpng-1.2.2-24.ppc.rpm
File outdated by:  RHSA-2010:0534
    MD5: 3f9f8f07958ccdbdae1dd5658d1f660d
libpng-1.2.2-24.ppc64.rpm
File outdated by:  RHSA-2010:0534
    MD5: a28f7104fa22ffba7c9c972721726efa
libpng-devel-1.2.2-24.ppc.rpm
File outdated by:  RHSA-2010:0534
    MD5: 935fbe2f7afb316145a9d3ec738718be
ftp://updates.redhat.com/rhn/repository/NULL/libpng-devel/1.2.2-24/ppc64/libpng-devel-1.2.2-24.ppc64.rpm
Missing file
    MD5: 5d557d5ecc04f15ad45007ded47c7b22
libpng10-1.0.13-14.ppc.rpm
File outdated by:  RHSA-2010:0534
    MD5: 03469eece5ab2c757fce148964438f8a
libpng10-devel-1.0.13-14.ppc.rpm
File outdated by:  RHSA-2010:0534
    MD5: 882bd95074aba728c10e1b44f96a4de4
 
s390:
libpng-1.2.2-24.s390.rpm
File outdated by:  RHSA-2010:0534
    MD5: 99edb05b88fa05393594006cde3605a9
libpng-devel-1.2.2-24.s390.rpm
File outdated by:  RHSA-2010:0534
    MD5: 2a8b05e84202c872c84852b143480a98
libpng10-1.0.13-14.s390.rpm
File outdated by:  RHSA-2010:0534
    MD5: ee7bce6430e786d94ffb598f1f0cc842
libpng10-devel-1.0.13-14.s390.rpm
File outdated by:  RHSA-2010:0534
    MD5: 6d8ca64a3f82caa142ceae5be4a36817
 
s390x:
libpng-1.2.2-24.s390.rpm
File outdated by:  RHSA-2010:0534
    MD5: 99edb05b88fa05393594006cde3605a9
libpng-1.2.2-24.s390x.rpm
File outdated by:  RHSA-2010:0534
    MD5: 3b5305cb0962ffd7d1a7472f8416efc1
libpng-devel-1.2.2-24.s390x.rpm
File outdated by:  RHSA-2010:0534
    MD5: 294c94237c1caa1e3f7c71b21091c7c5
libpng10-1.0.13-14.s390x.rpm
File outdated by:  RHSA-2010:0534
    MD5: a3a639aceb65debb84ced820828611ed
libpng10-devel-1.0.13-14.s390x.rpm
File outdated by:  RHSA-2010:0534
    MD5: 34ab7cea51cf9f6b644787a746bf5726
 
x86_64:
libpng-1.2.2-24.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: af63ef937508fd3bc25bb54203e9d9da
libpng-1.2.2-24.x86_64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 56f6e9b47b537fe124b9ed874c379bcc
libpng-devel-1.2.2-24.x86_64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 36c04c69972678f7279991cbf49763ad
libpng10-1.0.13-14.x86_64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 8b12075058f65c087e97f88f9d63e027
libpng10-devel-1.0.13-14.x86_64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 14dd5f536db290d29895252af5a38b5e
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
libpng-1.2.2-24.src.rpm
File outdated by:  RHSA-2010:0534
    MD5: 955bd34890b25d65120f30250a75d2fb
libpng-1.2.2-24.src.rpm
File outdated by:  RHSA-2010:0534
    MD5: 955bd34890b25d65120f30250a75d2fb
libpng10-1.0.13-14.src.rpm
File outdated by:  RHSA-2010:0534
    MD5: 4959b14e2264df985dacfac43e24df40
libpng10-1.0.13-14.src.rpm
File outdated by:  RHSA-2010:0534
    MD5: 4959b14e2264df985dacfac43e24df40
 
IA-32:
libpng-1.2.2-24.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: af63ef937508fd3bc25bb54203e9d9da
libpng-devel-1.2.2-24.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: 80f1c12114bf5648ccf56c270a3dcd5e
libpng10-1.0.13-14.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: 645136e04ec539eabf6c9f8106f62f47
libpng10-devel-1.0.13-14.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: d42c29c9604d0b2db4af78f5875bb468
 
IA-64:
libpng-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 4c046aafa3cc058427ca2ffe3df4374c
libpng-devel-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2010:0534
    MD5: cd5181aeae289c6446d4458071c18d2c
libpng10-1.0.13-14.ia64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 5168760faafc399c90958c60412ce516
libpng10-devel-1.0.13-14.ia64.rpm
File outdated by:  RHSA-2010:0534
    MD5: fe4a1b47268982804c2068ba6158c8d2
 
x86_64:
libpng-1.2.2-24.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: af63ef937508fd3bc25bb54203e9d9da
libpng-1.2.2-24.x86_64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 56f6e9b47b537fe124b9ed874c379bcc
libpng-devel-1.2.2-24.x86_64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 36c04c69972678f7279991cbf49763ad
libpng10-1.0.13-14.x86_64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 8b12075058f65c087e97f88f9d63e027
libpng10-devel-1.0.13-14.x86_64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 14dd5f536db290d29895252af5a38b5e
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
libpng-1.2.2-24.src.rpm
File outdated by:  RHSA-2010:0534
    MD5: 955bd34890b25d65120f30250a75d2fb
libpng-1.2.2-24.src.rpm
File outdated by:  RHSA-2010:0534
    MD5: 955bd34890b25d65120f30250a75d2fb
libpng10-1.0.13-14.src.rpm
File outdated by:  RHSA-2010:0534
    MD5: 4959b14e2264df985dacfac43e24df40
libpng10-1.0.13-14.src.rpm
File outdated by:  RHSA-2010:0534
    MD5: 4959b14e2264df985dacfac43e24df40
 
IA-32:
libpng-1.2.2-24.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: af63ef937508fd3bc25bb54203e9d9da
libpng-devel-1.2.2-24.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: 80f1c12114bf5648ccf56c270a3dcd5e
libpng10-1.0.13-14.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: 645136e04ec539eabf6c9f8106f62f47
libpng10-devel-1.0.13-14.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: d42c29c9604d0b2db4af78f5875bb468
 
IA-64:
libpng-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 4c046aafa3cc058427ca2ffe3df4374c
libpng-devel-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2010:0534
    MD5: cd5181aeae289c6446d4458071c18d2c
libpng10-1.0.13-14.ia64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 5168760faafc399c90958c60412ce516
libpng10-devel-1.0.13-14.ia64.rpm
File outdated by:  RHSA-2010:0534
    MD5: fe4a1b47268982804c2068ba6158c8d2
 
x86_64:
libpng-1.2.2-24.i386.rpm
File outdated by:  RHSA-2010:0534
    MD5: af63ef937508fd3bc25bb54203e9d9da
libpng-1.2.2-24.x86_64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 56f6e9b47b537fe124b9ed874c379bcc
libpng-devel-1.2.2-24.x86_64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 36c04c69972678f7279991cbf49763ad
libpng10-1.0.13-14.x86_64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 8b12075058f65c087e97f88f9d63e027
libpng10-devel-1.0.13-14.x86_64.rpm
File outdated by:  RHSA-2010:0534
    MD5: 14dd5f536db290d29895252af5a38b5e
 

References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/