UbuntuUpdates.org

Package "libpng12-0"

Name: libpng12-0

Description:

PNG library - runtime

Latest version: 1.2.50-1ubuntu2.14.04.3
Release: trusty (14.04)
Level: updates
Repository: main
Head package: libpng
Homepage: http://libpng.org/pub/png/libpng.html

Links


Download "libpng12-0"


Other versions of "libpng12-0" in Trusty

Repository Area Version
base main 1.2.50-1ubuntu2
security main 1.2.50-1ubuntu2.14.04.3

Changelog

Version: 1.2.50-1ubuntu2.14.04.3 2018-07-11 16:07:00 UTC

  libpng (1.2.50-1ubuntu2.14.04.3) trusty-security; urgency=medium

  * SECURITY UPDATE: Null pointer dereference
    - debian/patches/CVE-2016-10087.patch: fix in png.c.
    - CVE-2016-10087

 -- <email address hidden> (Leonidas S. Barbosa) Tue, 10 Jul 2018 16:58:16 -0300

Source diff to previous version
CVE-2016-10087 The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allo

Version: 1.2.50-1ubuntu2.14.04.2 2016-01-06 20:06:23 UTC

  libpng (1.2.50-1ubuntu2.14.04.2) trusty-security; urgency=medium

  * SECURITY UPDATE: overflows in png_handle_zTXt(), png_handle_sPLT(),
    png_handle_pCAL(), and png_set_PLTE()
    - debian/patches/CVE-2015-8472.patch: check lengths in pngrutil.c,
      properly use info_ptr in pngset.c.
    - CVE-2015-8472
  * SECURITY UPDATE: out-of-range read in png_check_keyword()
    - debian/patches/CVE-2015-8540.patch: check key_len in pngwutil.c.
    - CVE-2015-8540

 -- Marc Deslauriers Fri, 18 Dec 2015 09:54:17 -0500

Source diff to previous version
CVE-2015-8472 Incomplete fix for CVE-2015-8126
CVE-2015-8540 underflow read in png_check_keyword in pngwutil.c

Version: 1.2.50-1ubuntu2.14.04.1 2015-11-19 21:06:37 UTC

  libpng (1.2.50-1ubuntu2.14.04.1) trusty-security; urgency=medium

  [ Andrew Starr-Bochicchio ]
  * SECURITY UPDATE: Multiple buffer overflows in the (1) png_set_PLTE
    and (2) png_get_PLTE (LP: #1516592).
    - debian/patches/CVE-2015-8126.diff: Prevent writing over-length
      PLTE chunk and silently truncate over-length PLTE chunk while reading.
      Backported from upstream patch.
    - CVE-2015-8126

  [ Marc Deslauriers ]
  * SECURITY UPDATE: out of bounds read in png_set_tIME
    - debian/patches/CVE-2015-7981.patch: check bounds in png.c and
      pngset.c.
    - CVE-2015-7981

 -- Marc Deslauriers Thu, 19 Nov 2015 08:02:50 -0500

1516592 CVE-2015-8126: Multiple buffer overflows
CVE-2015-8126 Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.
CVE-2015-7981 read out of bound



About   -   Send Feedback to @ubuntu_updates