libpng security-patch updates
Greg Roelofs <[email protected]> Sat, 31 Jul 2004 11:54:39 -0700
| Newsgroups | gmane.comp.graphics.png.announce,gmane.comp.graphics.png.devel |
|---|---|
| Message-ID | <[email protected]> |
Glenn and I have uploaded new security patches to our respective libpng
pages:
http://sourceforge.net/project/showfiles.php?group_id=5624
(new "1.2.5-security-patches" group; also applies to 1.0.15)
http://www.libpng.org/pub/png/libpng.html
The ones that Glenn has labelled patch00 and patch02 and that I've
called patch 2 and patch 3 (for 1.2.5) are old; the only new one is
patch01/patch 4, respectively, which is actually the other half of
patch00/patch 2. That is, the older patch fixed only the 16bps RGBX-
filler case; the new one fixes the same problem for the GX-filler
(grayscale) case. The oversight came about in part because the
original Debian advisory included only the former fix, and that then
became known as "the" CAN-2002-1363 patch.
It's not clear to me that the filler vulnerability is widely applicable
(I think I've used png_set_filler() only once myself), but it may be.
In any case, if you compile and install your own shared version of
libpng, you should probably grab the patch(es) and recompile to be safe.
Greg
P.S. This is bcc'd to the -announce list, but please direct any replies
_only_ to png-implement. (I can't remember if png-announce sets
the Reply-to header correctly.)
--
Send the message body "help" to [email protected]