| Summary: | libpng (1.5.x) and libpng12 new security issue CVE-2013-6954 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | cmrisolde, mageia, rverschelde, stormi-mageia, sysadmin-bugs, tmb |
| Version: | 4 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/581308/ | ||
| Whiteboard: | MGA3TOO has_procedure mga3-32-ok mga3-64-ok mga4-32-ok mga4-64-ok advisory | ||
| Source RPM: | libpng12-1.2.50-3.mga3.src.rpm, libpng-1.5.13-2.mga3.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2014-02-12 20:54:43 CET
David Walser
2014-02-12 20:54:55 CET
Whiteboard:
(none) =>
MGA3TOO Testing procedure, feel free to add to it. If using it in the future, check that it's still valid with urpmq --whatrequires-recursive name_of_the_lib, especially for libpng12_0 because more and more packages switch to a newer libpng. For libpng12, usually we test by opening some png files with xv, which depends on lib(64)png12_0. gcompris uses it too, indirectly, so try it. For libpng15_15, lots of packages depend on it, including lots of games and viewers. Example : check that warmux and smc work well. Check that firefox can open a png file (don't forget to restart it after installing the update). We also need to test png transformations, so use graphicsmagick to perform some transformations. 1Testing procedure for graphicsmagick : https://wiki.mageia.org/en/QA_procedure:GraphicsMagick CC:
(none) =>
stormi Used sam2p (which links against libpng12_0) to convert a png to a PDF on M4-64. Worked fine for me. (In reply to Colin Guthrie from comment #2) > Used sam2p (which links against libpng12_0) to convert a png to a PDF on > M4-64. Worked fine for me. Good addition to the procedure, it lacked transformations using libpng12_0 Did the same test in M3-64 for libpng12 part and looked at some pngs in firefox for the libpng15 part. (also adding tag for the m4-64 test from previous comment) CC:
(none) =>
mageia Tested on Mga 32-bit - opening png images in firefox, xv, gwenview, ristretto; transformations using graphicsmagick as per procedure page and using sam2p as done by Colin. No regressions found after update. CC:
(none) =>
isolde Testing complete on Mageia 4 i586. -- Validating update, both advisories (mga3 and mga4) have been uploaded. Please push to 3 & 4 core/updates. Keywords:
(none) =>
validated_update Mga3 update pushed: http://advisories.mageia.org/MGASA-2014-0075.html Mga4 update pushed: http://advisories.mageia.org/MGASA-2014-0076.html Status:
NEW =>
RESOLVED |