--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2018-043bd3349e
2018-08-04 21:45:12.206413
--------------------------------------------------------------------------------
Name : libpng
Product : Fedora 28
Version : 1.6.34
Release : 6.fc28
URL :
http://www.libpng.org/pub/png/
Summary : A library of functions for manipulating PNG image format files
Description :
The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files. PNG
is a bit-mapped graphics format similar to the GIF format. PNG was
created to replace the GIF format, since GIF uses a patented data
compression algorithm.
Libpng should be installed if you need to manipulate PNG format image
files.
--------------------------------------------------------------------------------
Update Information:
Fix for **CVE-2018-13785**.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Aug 1 2018 Nikola Forr�� <nforro(a)redhat.com> - 2:1.6.34-6
- Fix CVE-2018-13785 (#1599944)
* Fri Jul 13 2018 Fedora Release Engineering <releng(a)fedoraproject.org> -
2:1.6.34-5
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Tue Feb 20 2018 Nikola Forr�� <nforro(a)redhat.com> - 2:1.6.34-4
- Add missing gcc build dependency
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1599944 - CVE-2018-13785 libpng: Integer overflow and resultant
divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service
[fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1599944
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-043bd3349e' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------