[openSUSE-SU-2019:1530-1] Security update for libpng16

Severity Low
Affected Packages 22
CVEs 2

Security update for libpng16

This update for libpng16 fixes the following issues:

Security issues fixed:

  • CVE-2019-7317: Fixed a use-after-free vulnerability, triggered when png_image_free() was called under png_safe_execute (bsc#1124211).
  • CVE-2018-13785: Fixed a wrong calculation of row_factor in the png_check_chunk_length function in pngrutil.c, which could haved triggered and integer overflow and result in an divide-by-zero while processing a crafted PNG file, leading to a denial of service (bsc#1100687)

This update was imported from the SUSE:SLE-15:Update update project.

Package Affected Version
pkg:rpm/opensuse/libpng16-tools?arch=x86_64&distro=opensuse-leap-15.1 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-tools?arch=x86_64&distro=opensuse-leap-15.0 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-tools?arch=i586&distro=opensuse-leap-15.1 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-tools?arch=i586&distro=opensuse-leap-15.0 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-devel?arch=x86_64&distro=opensuse-leap-15.1 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-devel?arch=x86_64&distro=opensuse-leap-15.0 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-devel?arch=i586&distro=opensuse-leap-15.1 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-devel?arch=i586&distro=opensuse-leap-15.0 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-devel-32bit?arch=x86_64&distro=opensuse-leap-15.1 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-devel-32bit?arch=x86_64&distro=opensuse-leap-15.0 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-compat-devel?arch=x86_64&distro=opensuse-leap-15.1 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-compat-devel?arch=x86_64&distro=opensuse-leap-15.0 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-compat-devel?arch=i586&distro=opensuse-leap-15.1 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-compat-devel?arch=i586&distro=opensuse-leap-15.0 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-compat-devel-32bit?arch=x86_64&distro=opensuse-leap-15.1 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-compat-devel-32bit?arch=x86_64&distro=opensuse-leap-15.0 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-16?arch=x86_64&distro=opensuse-leap-15.1 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-16?arch=x86_64&distro=opensuse-leap-15.0 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-16?arch=i586&distro=opensuse-leap-15.1 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-16?arch=i586&distro=opensuse-leap-15.0 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-16-32bit?arch=x86_64&distro=opensuse-leap-15.1 < 1.6.34-lp151.3.3.1
pkg:rpm/opensuse/libpng16-16-32bit?arch=x86_64&distro=opensuse-leap-15.0 < 1.6.34-lp151.3.3.1
ID
openSUSE-SU-2019:1530-1
Severity
low
URL
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Q4HM5QQMXWECPZMLHD5SAWL5ZKD2JZWL/#Q4HM5QQMXWECPZMLHD5SAWL5ZKD2JZWL
Published
2019-06-07T15:14:56
(5 years ago)
Modified
2019-06-07T15:14:56
(5 years ago)
Rights
Copyright 2024 SUSE LLC. All rights reserved.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/opensuse/libpng16-tools?arch=x86_64&distro=opensuse-leap-15.1 opensuse libpng16-tools < 1.6.34-lp151.3.3.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/libpng16-tools?arch=x86_64&distro=opensuse-leap-15.0 opensuse libpng16-tools < 1.6.34-lp151.3.3.1 opensuse-leap-15.0 x86_64
Affected pkg:rpm/opensuse/libpng16-tools?arch=i586&distro=opensuse-leap-15.1 opensuse libpng16-tools < 1.6.34-lp151.3.3.1 opensuse-leap-15.1 i586
Affected pkg:rpm/opensuse/libpng16-tools?arch=i586&distro=opensuse-leap-15.0 opensuse libpng16-tools < 1.6.34-lp151.3.3.1 opensuse-leap-15.0 i586
Affected pkg:rpm/opensuse/libpng16-devel?arch=x86_64&distro=opensuse-leap-15.1 opensuse libpng16-devel < 1.6.34-lp151.3.3.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/libpng16-devel?arch=x86_64&distro=opensuse-leap-15.0 opensuse libpng16-devel < 1.6.34-lp151.3.3.1 opensuse-leap-15.0 x86_64
Affected pkg:rpm/opensuse/libpng16-devel?arch=i586&distro=opensuse-leap-15.1 opensuse libpng16-devel < 1.6.34-lp151.3.3.1 opensuse-leap-15.1 i586
Affected pkg:rpm/opensuse/libpng16-devel?arch=i586&distro=opensuse-leap-15.0 opensuse libpng16-devel < 1.6.34-lp151.3.3.1 opensuse-leap-15.0 i586
Affected pkg:rpm/opensuse/libpng16-devel-32bit?arch=x86_64&distro=opensuse-leap-15.1 opensuse libpng16-devel-32bit < 1.6.34-lp151.3.3.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/libpng16-devel-32bit?arch=x86_64&distro=opensuse-leap-15.0 opensuse libpng16-devel-32bit < 1.6.34-lp151.3.3.1 opensuse-leap-15.0 x86_64
Affected pkg:rpm/opensuse/libpng16-compat-devel?arch=x86_64&distro=opensuse-leap-15.1 opensuse libpng16-compat-devel < 1.6.34-lp151.3.3.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/libpng16-compat-devel?arch=x86_64&distro=opensuse-leap-15.0 opensuse libpng16-compat-devel < 1.6.34-lp151.3.3.1 opensuse-leap-15.0 x86_64
Affected pkg:rpm/opensuse/libpng16-compat-devel?arch=i586&distro=opensuse-leap-15.1 opensuse libpng16-compat-devel < 1.6.34-lp151.3.3.1 opensuse-leap-15.1 i586
Affected pkg:rpm/opensuse/libpng16-compat-devel?arch=i586&distro=opensuse-leap-15.0 opensuse libpng16-compat-devel < 1.6.34-lp151.3.3.1 opensuse-leap-15.0 i586
Affected pkg:rpm/opensuse/libpng16-compat-devel-32bit?arch=x86_64&distro=opensuse-leap-15.1 opensuse libpng16-compat-devel-32bit < 1.6.34-lp151.3.3.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/libpng16-compat-devel-32bit?arch=x86_64&distro=opensuse-leap-15.0 opensuse libpng16-compat-devel-32bit < 1.6.34-lp151.3.3.1 opensuse-leap-15.0 x86_64
Affected pkg:rpm/opensuse/libpng16-16?arch=x86_64&distro=opensuse-leap-15.1 opensuse libpng16-16 < 1.6.34-lp151.3.3.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/libpng16-16?arch=x86_64&distro=opensuse-leap-15.0 opensuse libpng16-16 < 1.6.34-lp151.3.3.1 opensuse-leap-15.0 x86_64
Affected pkg:rpm/opensuse/libpng16-16?arch=i586&distro=opensuse-leap-15.1 opensuse libpng16-16 < 1.6.34-lp151.3.3.1 opensuse-leap-15.1 i586
Affected pkg:rpm/opensuse/libpng16-16?arch=i586&distro=opensuse-leap-15.0 opensuse libpng16-16 < 1.6.34-lp151.3.3.1 opensuse-leap-15.0 i586
Affected pkg:rpm/opensuse/libpng16-16-32bit?arch=x86_64&distro=opensuse-leap-15.1 opensuse libpng16-16-32bit < 1.6.34-lp151.3.3.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/libpng16-16-32bit?arch=x86_64&distro=opensuse-leap-15.0 opensuse libpng16-16-32bit < 1.6.34-lp151.3.3.1 opensuse-leap-15.0 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...