Your message dated Fri, 15 Jul 2011 03:32:22 +0000
with message-id <[email protected]>
and subject line Bug#633871: fixed in libpng 1.5.4-1
has caused the Debian Bug report #633871,
regarding Three security issues
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
633871: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=633871
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: libpng
Severity: grave
Tags: security

Three security issues have been reported in libpng. Please see
the following links to CVE IDs and Red Hat bugzilla:

1. buffer overwrite in png_rgb_to_gray
CVE: CVE-2011-2690
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=720607

2. Crash in png_default_error due to use of NULL Pointer
CVE: CVE-2011-2691
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=720608

3. Memory corruption when handling empty sCAL chunks
CVE: CVE-2011-2692
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=720612

Cheers,
        Moritz



--- End Message ---
--- Begin Message ---
Source: libpng
Source-Version: 1.5.4-1

We believe that the bug you reported is fixed in the latest version of
libpng, which is due to be installed in the Debian FTP archive:

libpng-dev_1.5.4-1_amd64.deb
  to main/libp/libpng/libpng-dev_1.5.4-1_amd64.deb
libpng15-15-udeb_1.5.4-1_amd64.udeb
  to main/libp/libpng/libpng15-15-udeb_1.5.4-1_amd64.udeb
libpng15-15_1.5.4-1_amd64.deb
  to main/libp/libpng/libpng15-15_1.5.4-1_amd64.deb
libpng_1.5.4-1.debian.tar.bz2
  to main/libp/libpng/libpng_1.5.4-1.debian.tar.bz2
libpng_1.5.4-1.dsc
  to main/libp/libpng/libpng_1.5.4-1.dsc
libpng_1.5.4.orig.tar.gz
  to main/libp/libpng/libpng_1.5.4.orig.tar.gz



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Nobuhiro Iwamatsu <[email protected]> (supplier of updated libpng package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Fri, 15 Jul 2011 12:01:42 +0900
Source: libpng
Binary: libpng15-15 libpng-dev libpng15-15-udeb
Architecture: source amd64
Version: 1.5.4-1
Distribution: experimental
Urgency: low
Maintainer: Anibal Monsalve Salazar <[email protected]>
Changed-By: Nobuhiro Iwamatsu <[email protected]>
Description: 
 libpng-dev - PNG library - development
 libpng15-15 - PNG library - runtime
 libpng15-15-udeb - PNG library - minimal runtime library (udeb)
Closes: 633871
Changes: 
 libpng (1.5.4-1) experimental; urgency=low
 .
   * New upstream release (Closes: #633871).
     - Fix CVE: CVE-2011-2690
       Buffer overwrite in png_rgb_to_gray
     - CVE: CVE-2011-2691
       Crash in png_default_error due to use of NULL Pointer
     - CVE: CVE-2011-2692
       Memory corruption when handling empty sCAL chunks
     - Remove patches/02-632786-CVE-2011-2501.patch. Applied to upstream.
Checksums-Sha1: 
 ffcf1b0d56debc90c93b425388bfb13c276a34c2 1771 libpng_1.5.4-1.dsc
 3ff340169a74b40b299b491009f210bf5b312475 1019446 libpng_1.5.4.orig.tar.gz
 15a012a8482587e70e8f376afdb94e3ae5d26191 14534 libpng_1.5.4-1.debian.tar.bz2
 20bf6386cb271a541f6121b2b9cea351b003e171 166504 libpng15-15_1.5.4-1_amd64.deb
 5eb7e50a67ad12d8cc9a27bf85df6be23963e2c3 295002 libpng-dev_1.5.4-1_amd64.deb
 2c6cedbab9bced7b94af4af1c6acfc9067a53828 79642 
libpng15-15-udeb_1.5.4-1_amd64.udeb
Checksums-Sha256: 
 917bfae0da0ba8b6e769c3154ec9bd00dfc1b5aaf9d85113d01ed22e41bdc182 1771 
libpng_1.5.4-1.dsc
 a5ccdbb70c72b48d0a90daaa1aebcb94997ec3f3a19a7f497f53dc50c88feaab 1019446 
libpng_1.5.4.orig.tar.gz
 b7dfa1ae719d95a71a8ce57adacb2350bd1b01a11e086bab52834dad258bf48b 14534 
libpng_1.5.4-1.debian.tar.bz2
 33d7eabf92a62d3ca8e91d6b88ffe5fa300eac99a0b0d2b163baf4c0ddf19ceb 166504 
libpng15-15_1.5.4-1_amd64.deb
 cbc4b060f4b0e5637ba69ea3680c6e65f2387484dd195a07ff3489eb19691357 295002 
libpng-dev_1.5.4-1_amd64.deb
 b32b749895fa2227a48e772d0947b45a3871f08691b9559f7dff445a48fcc190 79642 
libpng15-15-udeb_1.5.4-1_amd64.udeb
Files: 
 5d39fa99b19302b59c36741e201d64bd 1771 libs optional libpng_1.5.4-1.dsc
 dea4d1fd671160424923e92ff0cdda78 1019446 libs optional libpng_1.5.4.orig.tar.gz
 f2856f74c9044117f1e143f520c85e53 14534 libs optional 
libpng_1.5.4-1.debian.tar.bz2
 73bdeb0c585d15a4649415d13aee0564 166504 libs optional 
libpng15-15_1.5.4-1_amd64.deb
 fd8be1a07f93837ef41e585c2f0cb076 295002 libdevel optional 
libpng-dev_1.5.4-1_amd64.deb
 c0d63a2e0d7a146ff5f4a0f675891675 79642 debian-installer extra 
libpng15-15-udeb_1.5.4-1_amd64.udeb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAEBCAAGBQJOH7EKAAoJEDIkf7tArR+mExQP+gIicFZrz+snOaUzkl9I7fZx
nbfvpDy4BGrnw8qUiISzUA+qHoTI5OloMprTQ4SVC2I/2h55nE+65XaXOikCw4k/
1B740uQJrf3rp07HeuyiXPcO5ggHRbuMnFl8FRcbMcyqM4/BEGld5vVGaZZtQjWR
Obs5MA0olZLXezBZYQT28xVO6Lfh2XxQ9HInpodw8IckZmBMDXGqXnD3pkLDPcA3
W+IlJ6+hwT/EUxjg7JApstZZX58aHz0caJ5D2q1/8I8LKffRwSDDnbitW/UrnWpi
m4JPdYo5kiI+kz3BsyPIi2SFMiv3rwNXD4zqHw/Q7DaTXPh+vBO78LNRcG0AT+ee
vFoqYB0IzZSlNU5i1iVSDMyL1omRMYzVSy9hXWIEW9WRrvF0Gf1j0gz6l3x7nVBY
bKD6a2toKchBdDAlRUZaz/HTarxa4aZjlb9dmTv3Ur0nnMFXhmK84oWPdZ85/UxR
d1XKAyH6lVxPe6CgIoC3vBypon7/F2QhikFBLId5/zdlvf6TMujje6yVvIahXo4x
UEKYn+LNBtL8VcxRDZMEwEwoQmBhihATY/2EDxBPL3MssnQAoElEZcEwjw0VcFCO
bTLCJ5MaBRE0Dkfc7tUVUQHeRv1finUIhm4IpodJp/PiGvZGgiebmk4RO90iFP+m
SKBHj56zeQ+IvMh57gir
=oats
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to