libpng-1.0.60, 1.2.50, 1.4.12, 1.5.12, and 1.6.0beta26 released to fix vulnerability

Glenn Randers-Pehrson <[email protected]> Tue, 10 Jul 2012 22:42:11 -0400
Newsgroups gmane.comp.graphics.png.announce
Message-ID <CA+PdXcu94A1nXVShw=5XTDG+C_kgfts_jrQ_V3jq64cf3mHK6g__26547.67976278$1341974561$gmane$org@mail.gmail.com>
libpng-1.0.60, 1.2.50, 1.4.12, 1.5.12, and 1.6.0beta26 are
available from
ftp://ftp.simplesystems.org/pub/png/src
and from
http://libpng.sf.net

version 1.0.60 and 1.2.50 [July 9, 2012]
  Changed "a+w" to "u+w" in Makefile.in to fix CVE-2012-3386.

version 1.4.12 [July 10, 2012]
  Added two images to contrib/pngsuite (1-bit and 2-bit transparent grayscale),
    and renamed three whose names were inconsistent with those in
    pngsuite/README.txt.
  Changed "a+w" to "u+w" in Makefile.in to fix CVE-2012-3386.

Version 1.5.12 [July 10, 2012]
  Removed scripts/makefile.cegcc from the *.zip and *.7z distributions; it
    depends on configure, which is not included in those archives.
  Changed "a+w" to "u+w" in Makefile.in to fix CVE-2012-3386.

Version 1.6.0beta26 [July 10, 2012]
  Removed scripts/makefile.cegcc from the *.zip and *.7z distributions; it
    depends on configure, which is not included in those archives.
  Moved scripts/chkfmt to contrib/tools.
  Changed "a+w" to "u+w" in Makefile.in to fix CVE-2012-3386.

The CVE-2012-3386 vulnerability only affects users when they
run "make distcheck" and have failed to set a umask that prevents
writing publicly-writable files.  This is really not a libpng
vulnerability but an automake vulnerability; however, we have
been delivering a Makefile.in that was created with a vulnerable
version of automake, so all of our Makefile.in files needed to be updated.

Note that no libpng *application" that was built with libpng-1.0.59,
1.2.49, 1.4.11, 1.5.11, or 1.6.0beta26 needs to be rebuilt.
An attack using this vulnerability is only effective while you
are running "make distcheck" while building libpng (or anything
else for that matter).

If you want to patch a previous release, just change the one
instance of "a+w" to "u+w" in Makefile.in.  If you run autogen.sh
to recreate Makefile.in with a version of automake prior to
version 1.11.6 or 1.12.2, you will have to make the same
change to your freshly-created Makefile.in.

I couldn't do the usual beta, rc release process because
the vulnerabililty was made public before I was notified
about it.  Fortunately there weren't any changes to the
libpng source files pending; only some supporting files
were renamed or removed from scripts and contrib/pngsuite,
so there was really nothing much that needed to be tested.

Glenn

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/