UbuntuUpdates.org

Package "optipng"

Name: optipng

Description:

advanced PNG (Portable Network Graphics) optimizer

Latest version: 0.6.4-1ubuntu0.14.04.2
Release: trusty (14.04)
Level: security
Repository: main
Homepage: http://optipng.sourceforge.net/

Links


Download "optipng"


Other versions of "optipng" in Trusty

Repository Area Version
base main 0.6.4-1build1
updates main 0.6.4-1ubuntu0.14.04.2

Changelog

Version: 0.6.4-1ubuntu0.14.04.2 2017-11-27 20:06:39 UTC

  optipng (0.6.4-1ubuntu0.14.04.2) trusty-security; urgency=medium

  * SECURITY UPDATE: integer overflow in minitiff_read_info
    - debian/patches/CVE-2017-1000229.patch: add count check in
      lib/pngxtern/minitiff/tiffread.c.
    - CVE-2017-1000229

 -- Marc Deslauriers <email address hidden> Thu, 23 Nov 2017 13:45:05 -0500

Source diff to previous version

Version: 0.6.4-1ubuntu0.14.04.1 2016-04-18 14:07:02 UTC

  optipng (0.6.4-1ubuntu0.14.04.1) trusty-security; urgency=medium

  * SECURITY UPDATE: out of bounds read/writes via malformed image
    - debian/patches/CVE-2016-2191.patch: properly check bounds in
      src/pngxtern/pngxrbmp.c.
    - CVE-2016-2191
  * SECURITY UPDATE: denial of service via use-after-free
    - debian/patches/CVE-2015-7801.patch: fix free in src/opngoptim.c.
    - CVE-2015-7801
  * SECURITY UPDATE: harmless out-of-bounds read
    - debian/patches/CVE-2015-7802.patch: properly set last_byte in
      src/gifread/gifread.c.
    - CVE-2015-7802

 -- Marc Deslauriers <email address hidden> Wed, 13 Apr 2016 13:57:46 -0400

CVE-2016-2191 Invalid write while processing delta escapes without any boundary checking
CVE-2015-7801 Use after free
CVE-2015-7802 Global buffer under-read



About   -   Send Feedback to @ubuntu_updates