[SECURITY] Fedora 12 Update: libpng10-1.0.53-1.fc12

updates at fedoraproject.org updates at fedoraproject.org
Tue Mar 16 00:49:31 UTC 2010

Fedora Update Notification
2010-03-03 01:36:11

Name        : libpng10
Product     : Fedora 12
Version     : 1.0.53
Release     : 1.fc12
URL         : http://www.libpng.org/pub/png/libpng.html
Summary     : Old version of libpng, needed to run old binaries
Description :
The libpng10 package contains an old version of libpng, a library of functions
for creating and manipulating PNG (Portable Network Graphics) image format

This package is needed if you want to run binaries that were linked dynamically
with libpng 1.0.x.

Update Information:

This is the latest upstream maintenance release.    In addition to a number of
minor bugfixes, it mitigates the resource-consumption effects of highly
compressed ancillary chunks in hostile PNG files as described at
http://libpng.sourceforge.net/ADVISORY-1.4.1.html    This issue has been
assigned CVE-2010-0205 by CERT.

* Thu Feb 25 2010 Paul Howarth <paul at city-fan.org> 1.0.53-1
- update to 1.0.53 (minor changes, see ANNOUNCE for details)
- drop patch for #555485, included upstream
* Thu Jan  7 2010 Paul Howarth <paul at city-fan.org> 1.0.52-2
- add upstream fix reinstating PNG_READ_16_TO_8_SUPPORTED and
  PNG_READ_GRAY_TO_RGB_SUPPORTED (not defined in 1.0.51 and 1.0.52),
  causing API/ABI regressions (#555485)
* Mon Jan  4 2010 Paul Howarth <paul at city-fan.org> 1.0.52-1
- update to 1.0.52 (minor changes, see ANNOUNCE for details)
* Thu Dec  3 2009 Paul Howarth <paul at city-fan.org> 1.0.51-1
- update to 1.0.51 (see ANNOUNCE for details)
- update soname patch to apply to 1.0.51

  [ 1 ] Bug #566234 - CVE-2010-0205 libpng: excessive memory consumption due to highly compressed huge ancillary chunk

This update can be installed with the "yum" update program.  Use 
su -c 'yum update libpng10' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at

More information about the package-announce mailing list