[ubuntu/jaunty-security] libpng, libpng (delayed) 1.2.27-2ubuntu2.1 (Accepted)

Ubuntu Installer archive at ubuntu.com
Tue Mar 16 17:05:43 GMT 2010


libpng (1.2.27-2ubuntu2.1) jaunty-security; urgency=low

  * SECURITY UPDATE: denial of service via decompression bomb (LP: #533140)
    - debian/patches/03-CVE-2010-0205.patch: use new two-pass decompression
      method in pngrutil.c.
    - CVE-2010-0205
  * SECURITY UPDATE: information disclosure via 1-bit interlaced images
    - debian/patches/04-CVE-2009-2042.patch: initialize memory in
      pngrutil.c.
    - CVE-2009-2042

Date: Mon, 15 Mar 2010 11:00:47 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/jaunty/+source/libpng/1.2.27-2ubuntu2.1
-------------- next part --------------
Format: 1.8
Date: Mon, 15 Mar 2010 11:00:47 -0400
Source: libpng
Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb
Architecture: source
Version: 1.2.27-2ubuntu2.1
Distribution: jaunty-security
Urgency: low
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description: 
 libpng12-0 - PNG library - runtime
 libpng12-0-udeb - PNG library - minimal runtime library (udeb)
 libpng12-dev - PNG library - development
 libpng3    - PNG library - runtime
Launchpad-Bugs-Fixed: 533140
Changes: 
 libpng (1.2.27-2ubuntu2.1) jaunty-security; urgency=low
 .
   * SECURITY UPDATE: denial of service via decompression bomb (LP: #533140)
     - debian/patches/03-CVE-2010-0205.patch: use new two-pass decompression
       method in pngrutil.c.
     - CVE-2010-0205
   * SECURITY UPDATE: information disclosure via 1-bit interlaced images
     - debian/patches/04-CVE-2009-2042.patch: initialize memory in
       pngrutil.c.
     - CVE-2009-2042
Checksums-Sha1: 
 5a762072571824505a429abbe4cab6146e96b166 1296 libpng_1.2.27-2ubuntu2.1.dsc
 e9f28d0f8901cd80a7327d894366948740deb50b 174503 libpng_1.2.27-2ubuntu2.1.diff.gz
Checksums-Sha256: 
 73bafb099b10ba72d7788ad04a5745967bef0eebfb33af6e9ef07fbd71979722 1296 libpng_1.2.27-2ubuntu2.1.dsc
 037727f2de191c0c5fbe48b113884ff907aa4771c5002d22e91c523d0ee64725 174503 libpng_1.2.27-2ubuntu2.1.diff.gz
Files: 
 890ff19ff7b12aa90d0d38c0b1550055 1296 libs optional libpng_1.2.27-2ubuntu2.1.dsc
 ffa63cd1b57dc442faff9a65d2f25ee7 174503 libs optional libpng_1.2.27-2ubuntu2.1.diff.gz
Original-Maintainer: Anibal Monsalve Salazar <anibal at debian.org>


More information about the Jaunty-changes mailing list