Bug 12077

Summary: libpng new security issue CVE-2013-6954
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Funda Wang <fundawang>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: oe
Version: Cauldron   
Target Milestone: ---   
Hardware: i586   
OS: Linux   
URL: http://lwn.net/Vulnerabilities/581308/
Whiteboard:
Source RPM: libpng-1.6.7-1.mga4.src.rpm CVE:
Status comment:

Description David Walser 2013-12-22 07:11:53 CET
Upstream has released version 1.6.8 on December 21:
http://freecode.com/projects/libpng/releases/360062

I would have updated it already, but the apng for 1.6.8 isn't available yet.

Reproducible: 

Steps to Reproduce:
Comment 1 Oden Eriksson 2013-12-23 13:56:06 CET
1.6.8 has been committed to cauldron, needs submission.

CC: (none) => oe

Comment 2 David Walser 2013-12-23 14:38:47 CET
Thanks Oden.  Freeze push requested.
Comment 3 David Walser 2013-12-23 16:38:36 CET
libpng-1.6.8-1.mga4 uploaded.

Status: NEW => RESOLVED
Resolution: (none) => FIXED

David Walser 2014-01-21 17:33:01 CET

URL: (none) => http://lwn.net/Vulnerabilities/581308/