Oval Definition:oval:org.opensuse.security:def:90146
Revision Date:2019-07-05Version:1
Title:Security update for libpng16 (Low)
Description:

This update for libpng16 fixes the following issues:

Security issues fixed:

- CVE-2019-7317: Fixed a use-after-free vulnerability, triggered when png_image_free() was called under png_safe_execute (bsc#1124211). - CVE-2018-13785: Fixed a wrong calculation of row_factor in the png_check_chunk_length function in pngrutil.c, which could haved triggered and integer overflow and result in an divide-by-zero while processing a crafted PNG file, leading to a denial of service (bsc#1100687)
Family:unixClass:patch
Status:Reference(s):1100687
1121624
1124211
CVE-2018-13785
CVE-2019-7317
SUSE-SU-2019:1398-2
Platform(s):SUSE Linux Enterprise Desktop 15 SP1
SUSE Linux Enterprise High Performance Computing 15 SP1
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Server 15 SP1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Linux Enterprise Storage 6
SUSE Manager Proxy 4.0
SUSE Manager Server 4.0
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • libpng16-16-1.6.34-3.9.1 is installed
  • OR libpng16-16-32bit-1.6.34-3.9.1 is installed
  • OR libpng16-compat-devel-1.6.34-3.9.1 is installed
  • OR libpng16-devel-1.6.34-3.9.1 is installed
  • BACK