UbuntuUpdates.org

Package "libpng"

Name: libpng

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • PNG library - runtime

Latest version: 1.2.46-3ubuntu4.3
Release: precise (12.04)
Level: updates
Repository: universe

Links



Other versions of "libpng" in Precise

Repository Area Version
base main 1.2.46-3ubuntu4
base universe 1.2.46-3ubuntu4
security main 1.2.46-3ubuntu4.3
security universe 1.2.46-3ubuntu4.3
updates main 1.2.46-3ubuntu4.3

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.2.46-3ubuntu4.3 2021-05-03 16:06:23 UTC

  libpng (1.2.46-3ubuntu4.3) precise-security; urgency=medium

  * SECURITY UPDATE: Null pointer dereference
    - debian/patches/CVE-2016-10087.patch: fix in png.c.
    - CVE-2016-10087

 -- <email address hidden> (Leonidas S. Barbosa) Tue, 10 Jul 2018 16:56:50 -0300

Source diff to previous version
CVE-2016-10087 The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allo

Version: 1.2.46-3ubuntu4.2 2016-01-06 20:06:22 UTC

  libpng (1.2.46-3ubuntu4.2) precise-security; urgency=medium

  * SECURITY UPDATE: overflows in png_handle_zTXt(), png_handle_sPLT(),
    png_handle_pCAL(), and png_set_PLTE()
    - debian/patches/CVE-2015-8472.patch: check lengths in pngrutil.c,
      properly use info_ptr in pngset.c.
    - CVE-2015-8472
  * SECURITY UPDATE: out-of-range read in png_check_keyword()
    - debian/patches/CVE-2015-8540.patch: check key_len in pngwutil.c.
    - CVE-2015-8540

 -- Marc Deslauriers Fri, 18 Dec 2015 09:54:56 -0500

Source diff to previous version
CVE-2015-8472 Incomplete fix for CVE-2015-8126
CVE-2015-8540 underflow read in png_check_keyword in pngwutil.c

Version: 1.2.46-3ubuntu4.1 2015-11-19 21:06:34 UTC

  libpng (1.2.46-3ubuntu4.1) precise-security; urgency=medium

  [ Andrew Starr-Bochicchio ]
  * SECURITY UPDATE: Multiple buffer overflows in the (1) png_set_PLTE
    and (2) png_get_PLTE (LP: #1516592).
    - debian/patches/CVE-2015-8126.diff: Prevent writing over-length
      PLTE chunk and silently truncate over-length PLTE chunk while reading.
      Backported from upstream patch.
    - CVE-2015-8126

  [ Marc Deslauriers ]
  * SECURITY UPDATE: out of bounds read in png_set_tIME
    - debian/patches/CVE-2015-7981.patch: check bounds in png.c and
      pngset.c.
    - CVE-2015-7981
  * SECURITY UPDATE: out of bounds read in png_push_read_zTXt
    - debian/patches/CVE-2012-3425.patch: check for truncated chunk in
      pngpread.c.
    - CVE-2012-3425

 -- Marc Deslauriers Thu, 19 Nov 2015 08:05:59 -0500

1516592 CVE-2015-8126: Multiple buffer overflows
CVE-2015-8126 Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.
CVE-2015-7981 read out of bound
CVE-2012-3425 The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows



About   -   Send Feedback to @ubuntu_updates