Re: libpng-1.0.60, 1.2.50, 1.4.12, 1.5.12, and 1.6.0beta26 released to fix vulnerability

[email protected] Thu, 12 Jul 2012 14:36:21 +0000 (UTC)
Newsgroups gmane.comp.graphics.png.announce
Message-ID <1742936085.1219682.1342103781236.JavaMail.root__31020.3052861199$1342103822$gmane$org@sz0023a.westchester.pa.mail.comcast.net>
----- Greg Roelofs <[email protected]> wrote:
> Glenn Randers-Pehrson <[email protected]> wrote:
> 
> > The CVE-2012-3386 vulnerability only affects users when they
> > run "make distcheck" and have failed to set a umask that prevents
> > writing publicly-writable files.
> 
> umask has no effect on chmod; all users who run "make distcheck" are
> affected (though only insofar as they make use of the freshly unpacked
> binaries or other files in $(distdir) in some way).

That is correct.  I misread something in the discussion of
the vulnerability.  I don't know how to change the CHANGES files
without making another release, but you can say something in libpng.html
to the effect that the statement about umask in the CHANGES should
be ignored and that the vulnerability exists even when the user
has properly set up a "secure" umask.

G

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/