Security Advisory libpng security update

Advisory: RHSA-2004:249-07
Type: Security Advisory
Severity: Important
Issued on: 2004-06-18
Last updated on: 2004-06-18
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 3)
OVAL: N/A
CVEs (cve.mitre.org): CVE-2002-1363

Details

Updated libpng packages that fix a possible buffer overflow are now available.

The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

During an audit of Red Hat Linux updates, the Fedora Legacy team found a
security issue in libpng that had not been fixed in Red Hat Enterprise
Linux 3. An attacker could carefully craft a PNG file in such a way that
it would cause an application linked to libpng to crash or potentially
execute arbitrary code when opened by a victim.

Note: this issue does not affect Red Hat Enterprise Linux 2.1

Users are advised to upgrade to these updated packages that contain a
backported security fix and are not vulnerable to this issue.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

If up2date fails to connect to Red Hat Network due to SSL
Certificate Errors, you need to install a version of the
up2date client with an updated certificate. The latest version of
up2date is available from the Red Hat FTP site and may also be
downloaded directly from the RHN website:

https://rhn.redhat.com/help/latest-up2date.pxt

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
libpng-1.2.2-24.src.rpm
File outdated by:  RHSA-2009:0340
    955bd34890b25d65120f30250a75d2fb
libpng10-1.0.13-14.src.rpm
File outdated by:  RHSA-2009:0340
    4959b14e2264df985dacfac43e24df40
 
IA-32:
libpng-1.2.2-24.i386.rpm
File outdated by:  RHSA-2009:0340
    af63ef937508fd3bc25bb54203e9d9da
libpng-devel-1.2.2-24.i386.rpm
File outdated by:  RHSA-2009:0340
    80f1c12114bf5648ccf56c270a3dcd5e
libpng10-1.0.13-14.i386.rpm
File outdated by:  RHSA-2009:0340
    645136e04ec539eabf6c9f8106f62f47
libpng10-devel-1.0.13-14.i386.rpm
File outdated by:  RHSA-2009:0340
    d42c29c9604d0b2db4af78f5875bb468
 
x86_64:
libpng-1.2.2-24.i386.rpm
File outdated by:  RHSA-2009:0340
    af63ef937508fd3bc25bb54203e9d9da
libpng-1.2.2-24.x86_64.rpm
File outdated by:  RHSA-2009:0340
    56f6e9b47b537fe124b9ed874c379bcc
libpng-devel-1.2.2-24.x86_64.rpm
File outdated by:  RHSA-2009:0340
    36c04c69972678f7279991cbf49763ad
libpng10-1.0.13-14.x86_64.rpm
File outdated by:  RHSA-2009:0340
    8b12075058f65c087e97f88f9d63e027
libpng10-devel-1.0.13-14.x86_64.rpm
File outdated by:  RHSA-2009:0340
    14dd5f536db290d29895252af5a38b5e
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
libpng-1.2.2-24.src.rpm
File outdated by:  RHSA-2009:0340
    955bd34890b25d65120f30250a75d2fb
libpng10-1.0.13-14.src.rpm
File outdated by:  RHSA-2009:0340
    4959b14e2264df985dacfac43e24df40
 
IA-32:
libpng-1.2.2-24.i386.rpm
File outdated by:  RHSA-2009:0340
    af63ef937508fd3bc25bb54203e9d9da
libpng-devel-1.2.2-24.i386.rpm
File outdated by:  RHSA-2009:0340
    80f1c12114bf5648ccf56c270a3dcd5e
libpng10-1.0.13-14.i386.rpm
File outdated by:  RHSA-2009:0340
    645136e04ec539eabf6c9f8106f62f47
libpng10-devel-1.0.13-14.i386.rpm
File outdated by:  RHSA-2009:0340
    d42c29c9604d0b2db4af78f5875bb468
 
IA-64:
libpng-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2009:0340
    4c046aafa3cc058427ca2ffe3df4374c
libpng-devel-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2009:0340
    cd5181aeae289c6446d4458071c18d2c
libpng10-1.0.13-14.ia64.rpm
File outdated by:  RHSA-2009:0340
    5168760faafc399c90958c60412ce516
libpng10-devel-1.0.13-14.ia64.rpm
File outdated by:  RHSA-2009:0340
    fe4a1b47268982804c2068ba6158c8d2
 
PPC:
libpng-1.2.2-24.ppc.rpm
File outdated by:  RHSA-2009:0340
    3f9f8f07958ccdbdae1dd5658d1f660d
libpng-1.2.2-24.ppc64.rpm
File outdated by:  RHSA-2009:0340
    a28f7104fa22ffba7c9c972721726efa
libpng-devel-1.2.2-24.ppc.rpm
File outdated by:  RHSA-2009:0340
    935fbe2f7afb316145a9d3ec738718be
libpng-devel-1.2.2-24.ppc64.rpm     5d557d5ecc04f15ad45007ded47c7b22
libpng10-1.0.13-14.ppc.rpm
File outdated by:  RHSA-2009:0340
    03469eece5ab2c757fce148964438f8a
libpng10-devel-1.0.13-14.ppc.rpm
File outdated by:  RHSA-2009:0340
    882bd95074aba728c10e1b44f96a4de4
 
s390:
libpng-1.2.2-24.s390.rpm
File outdated by:  RHSA-2009:0340
    99edb05b88fa05393594006cde3605a9
libpng-devel-1.2.2-24.s390.rpm
File outdated by:  RHSA-2009:0340
    2a8b05e84202c872c84852b143480a98
libpng10-1.0.13-14.s390.rpm
File outdated by:  RHSA-2009:0340
    ee7bce6430e786d94ffb598f1f0cc842
libpng10-devel-1.0.13-14.s390.rpm
File outdated by:  RHSA-2009:0340
    6d8ca64a3f82caa142ceae5be4a36817
 
s390x:
libpng-1.2.2-24.s390.rpm
File outdated by:  RHSA-2009:0340
    99edb05b88fa05393594006cde3605a9
libpng-1.2.2-24.s390x.rpm
File outdated by:  RHSA-2009:0340
    3b5305cb0962ffd7d1a7472f8416efc1
libpng-devel-1.2.2-24.s390x.rpm
File outdated by:  RHSA-2009:0340
    294c94237c1caa1e3f7c71b21091c7c5
libpng10-1.0.13-14.s390x.rpm
File outdated by:  RHSA-2009:0340
    a3a639aceb65debb84ced820828611ed
libpng10-devel-1.0.13-14.s390x.rpm
File outdated by:  RHSA-2009:0340
    34ab7cea51cf9f6b644787a746bf5726
 
x86_64:
libpng-1.2.2-24.i386.rpm
File outdated by:  RHSA-2009:0340
    af63ef937508fd3bc25bb54203e9d9da
libpng-1.2.2-24.x86_64.rpm
File outdated by:  RHSA-2009:0340
    56f6e9b47b537fe124b9ed874c379bcc
libpng-devel-1.2.2-24.x86_64.rpm
File outdated by:  RHSA-2009:0340
    36c04c69972678f7279991cbf49763ad
libpng10-1.0.13-14.x86_64.rpm
File outdated by:  RHSA-2009:0340
    8b12075058f65c087e97f88f9d63e027
libpng10-devel-1.0.13-14.x86_64.rpm
File outdated by:  RHSA-2009:0340
    14dd5f536db290d29895252af5a38b5e
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
libpng-1.2.2-24.src.rpm
File outdated by:  RHSA-2009:0340
    955bd34890b25d65120f30250a75d2fb
libpng10-1.0.13-14.src.rpm
File outdated by:  RHSA-2009:0340
    4959b14e2264df985dacfac43e24df40
 
IA-32:
libpng-1.2.2-24.i386.rpm
File outdated by:  RHSA-2009:0340
    af63ef937508fd3bc25bb54203e9d9da
libpng-devel-1.2.2-24.i386.rpm
File outdated by:  RHSA-2009:0340
    80f1c12114bf5648ccf56c270a3dcd5e
libpng10-1.0.13-14.i386.rpm
File outdated by:  RHSA-2009:0340
    645136e04ec539eabf6c9f8106f62f47
libpng10-devel-1.0.13-14.i386.rpm
File outdated by:  RHSA-2009:0340
    d42c29c9604d0b2db4af78f5875bb468
 
IA-64:
libpng-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2009:0340
    4c046aafa3cc058427ca2ffe3df4374c
libpng-devel-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2009:0340
    cd5181aeae289c6446d4458071c18d2c
libpng10-1.0.13-14.ia64.rpm
File outdated by:  RHSA-2009:0340
    5168760faafc399c90958c60412ce516
libpng10-devel-1.0.13-14.ia64.rpm
File outdated by:  RHSA-2009:0340
    fe4a1b47268982804c2068ba6158c8d2
 
x86_64:
libpng-1.2.2-24.i386.rpm
File outdated by:  RHSA-2009:0340
    af63ef937508fd3bc25bb54203e9d9da
libpng-1.2.2-24.x86_64.rpm
File outdated by:  RHSA-2009:0340
    56f6e9b47b537fe124b9ed874c379bcc
libpng-devel-1.2.2-24.x86_64.rpm
File outdated by:  RHSA-2009:0340
    36c04c69972678f7279991cbf49763ad
libpng10-1.0.13-14.x86_64.rpm
File outdated by:  RHSA-2009:0340
    8b12075058f65c087e97f88f9d63e027
libpng10-devel-1.0.13-14.x86_64.rpm
File outdated by:  RHSA-2009:0340
    14dd5f536db290d29895252af5a38b5e
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
libpng-1.2.2-24.src.rpm
File outdated by:  RHSA-2009:0340
    955bd34890b25d65120f30250a75d2fb
libpng10-1.0.13-14.src.rpm
File outdated by:  RHSA-2009:0340
    4959b14e2264df985dacfac43e24df40
 
IA-32:
libpng-1.2.2-24.i386.rpm
File outdated by:  RHSA-2009:0340
    af63ef937508fd3bc25bb54203e9d9da
libpng-devel-1.2.2-24.i386.rpm
File outdated by:  RHSA-2009:0340
    80f1c12114bf5648ccf56c270a3dcd5e
libpng10-1.0.13-14.i386.rpm
File outdated by:  RHSA-2009:0340
    645136e04ec539eabf6c9f8106f62f47
libpng10-devel-1.0.13-14.i386.rpm
File outdated by:  RHSA-2009:0340
    d42c29c9604d0b2db4af78f5875bb468
 
IA-64:
libpng-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2009:0340
    4c046aafa3cc058427ca2ffe3df4374c
libpng-devel-1.2.2-24.ia64.rpm
File outdated by:  RHSA-2009:0340
    cd5181aeae289c6446d4458071c18d2c
libpng10-1.0.13-14.ia64.rpm
File outdated by:  RHSA-2009:0340
    5168760faafc399c90958c60412ce516
libpng10-devel-1.0.13-14.ia64.rpm
File outdated by:  RHSA-2009:0340
    fe4a1b47268982804c2068ba6158c8d2
 
x86_64:
libpng-1.2.2-24.i386.rpm
File outdated by:  RHSA-2009:0340
    af63ef937508fd3bc25bb54203e9d9da
libpng-1.2.2-24.x86_64.rpm
File outdated by:  RHSA-2009:0340
    56f6e9b47b537fe124b9ed874c379bcc
libpng-devel-1.2.2-24.x86_64.rpm
File outdated by:  RHSA-2009:0340
    36c04c69972678f7279991cbf49763ad
libpng10-1.0.13-14.x86_64.rpm
File outdated by:  RHSA-2009:0340
    8b12075058f65c087e97f88f9d63e027
libpng10-devel-1.0.13-14.x86_64.rpm
File outdated by:  RHSA-2009:0340
    14dd5f536db290d29895252af5a38b5e
 
(The unlinked packages above are only available from the Red Hat Network)

References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/