Bug 5041 - libpng new security issue CVE-2011-3045
Summary: libpng new security issue CVE-2011-3045
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 1
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL:
Whiteboard:
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2012-03-21 13:32 CET by David Walser
Modified: 2012-03-24 16:10 CET (History)
2 users (show)

See Also:
Source RPM: libpng-1.2.47-1.mga1.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2012-03-21 13:32:19 CET
Mandriva issued this advisory today (March 21):
http://www.mandriva.com/en/support/security/advisories/?dis=2010.1&name=MDVSA-2012:033

It looks like only libpng 1.2 is affected.  Cauldron should be affected as well.

We can patch it or update to 1.2.48.
Manuel Hiebel 2012-03-21 22:21:06 CET

Assignee: bugsquad => fundawang

David Walser 2012-03-22 03:06:31 CET

Blocks: (none) => 5046

Comment 1 Funda Wang 2012-03-22 06:00:41 CET
New version of package (libpng 1.2.48) pushed in core/updates_testing. Please test

Status: NEW => ASSIGNED
Assignee: fundawang => qa-bugs

David Walser 2012-03-22 13:58:04 CET

Blocks: 5046 => (none)

Comment 2 David Walser 2012-03-22 14:13:22 CET
Advisory:
========================

Updated libpng packages fix security vulnerability:

A heap-based buffer overflow flaw was found in the way libpng
processed compressed chunks in PNG image files. An attacker could
create a specially-crafted PNG image file that, when opened, could
cause an application using libpng to crash or, possibly, execute
arbitrary code with the privileges of the user running the application
(CVE-2011-3045).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3045
https://bugzilla.redhat.com/show_bug.cgi?id=799000
http://www.mandriva.com/en/support/security/advisories/?dis=2010.1&name=MDVSA-2012:033
========================

Updated packages in core/updates_testing:
========================
libpng-devel-1.2.48-1.mga1
libpng-source-1.2.48-1.mga1
libpng-static-devel-1.2.48-1.mga1
libpng3-1.2.48-1.mga1

from libpng-1.2.48-1.mga1.src.rpm
Comment 3 claire robinson 2012-03-22 14:30:36 CET
Test OK x86_64 with xv some.png
Comment 4 claire robinson 2012-03-23 13:48:23 CET
Tested OK i586, same procedure

Validating.

Advisory and SRPM in comment 2

Could sysadmin please push from core/updates_testing to core/updates

Thankyou!

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs
Hardware: i586 => All

Comment 5 Thomas Backlund 2012-03-24 16:10:14 CET
Update pushed.

Status: ASSIGNED => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.