Oval Definition:oval:com.redhat.rhsa:def:20070356
Revision Date:2007-05-17Version:635
Title:RHSA-2007:0356: libpng security update (Moderate)
Description:The libpng package contains a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files.

  • A flaw was found in the handling of malformed images in libpng. An attacker could create a carefully crafted PNG image file in such a way that it could cause an application linked with libpng to crash when the file was manipulated. (CVE-2007-2445)

  • A flaw was found in the sPLT chunk handling code in libpng. An attacker could create a carefully crafted PNG image file in such a way that it could cause an application linked with libpng to crash when the file was opened. (CVE-2006-5793)

    Users of libpng should update to these updated packages which contain backported patches to correct these issues.

    Red Hat would like to thank Glenn Randers-Pehrson, Mats Palmgren, and Tavis Ormandy for supplying details and patches for these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2006-5793
    CVE-2007-2445
    RHSA-2007:0356
    RHSA-2007:0356-03
    RHSA-2007:0356-03
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • libpng-devel is earlier than 2:1.2.2-27
  • AND libpng-devel is signed with Red Hat master key
  • libpng is earlier than 2:1.2.2-27
  • AND libpng is signed with Red Hat master key
  • libpng10-devel is earlier than 0:1.0.13-17
  • AND libpng10-devel is signed with Red Hat master key
  • libpng10 is earlier than 0:1.0.13-17
  • AND libpng10 is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • libpng is earlier than 2:1.2.7-3.el4
  • AND libpng is signed with Red Hat master key
  • libpng-devel is earlier than 2:1.2.7-3.el4
  • AND libpng-devel is signed with Red Hat master key
  • libpng10 is earlier than 0:1.0.16-3
  • AND libpng10 is signed with Red Hat master key
  • libpng10-devel is earlier than 0:1.0.16-3
  • AND libpng10-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • libpng is earlier than 2:1.2.10-7.0.2
  • AND libpng is signed with Red Hat redhatrelease key
  • libpng-devel is earlier than 2:1.2.10-7.0.2
  • AND libpng-devel is signed with Red Hat redhatrelease key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • libpng is earlier than 2:1.2.2-27
  • AND libpng is signed with Red Hat master key
  • libpng-devel is earlier than 2:1.2.2-27
  • AND libpng-devel is signed with Red Hat master key
  • libpng10 is earlier than 0:1.0.13-17
  • AND libpng10 is signed with Red Hat master key
  • libpng10-devel is earlier than 0:1.0.13-17
  • AND libpng10-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • libpng is earlier than 2:1.2.7-3.el4
  • AND libpng is signed with Red Hat master key
  • libpng-devel is earlier than 2:1.2.7-3.el4
  • AND libpng-devel is signed with Red Hat master key
  • libpng10 is earlier than 0:1.0.16-3
  • AND libpng10 is signed with Red Hat master key
  • libpng10-devel is earlier than 0:1.0.16-3
  • AND libpng10-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • libpng is earlier than 2:1.2.10-7.0.2
  • AND libpng is signed with Red Hat redhatrelease key
  • libpng-devel is earlier than 2:1.2.10-7.0.2
  • AND libpng-devel is signed with Red Hat redhatrelease key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • libpng is earlier than 2:1.2.7-3.el4
  • AND libpng is signed with Red Hat redhatrelease2 key
  • libpng-devel is earlier than 2:1.2.7-3.el4
  • AND libpng-devel is signed with Red Hat redhatrelease2 key
  • libpng10 is earlier than 0:1.0.16-3
  • AND libpng10 is signed with Red Hat redhatrelease2 key
  • libpng10-devel is earlier than 0:1.0.16-3
  • AND libpng10-devel is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • libpng is earlier than 2:1.2.10-7.0.2
  • AND libpng is signed with Red Hat redhatrelease2 key
  • libpng-devel is earlier than 2:1.2.10-7.0.2
  • AND libpng-devel is signed with Red Hat redhatrelease2 key
  • BACK