[ubuntu/lucid] libpng 1.2.42-1ubuntu2 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Fri Mar 19 19:01:29 GMT 2010


libpng (1.2.42-1ubuntu2) lucid; urgency=low

  * SECURITY UPDATE: denial of service via decompression bomb (LP: #533140)
    - debian/patches/02-CVE-2010-0205.patch: use new two-pass decompression
      method in pngrutil.c.
    - CVE-2010-0205

Date: Thu, 11 Mar 2010 14:22:24 -0500
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/lucid/+source/libpng/1.2.42-1ubuntu2
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Thu, 11 Mar 2010 14:22:24 -0500
Source: libpng
Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb
Architecture: source
Version: 1.2.42-1ubuntu2
Distribution: lucid
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description: 
 libpng12-0 - PNG library - runtime
 libpng12-0-udeb - PNG library - minimal runtime library (udeb)
 libpng12-dev - PNG library - development
 libpng3    - PNG library - runtime
Launchpad-Bugs-Fixed: 533140
Changes: 
 libpng (1.2.42-1ubuntu2) lucid; urgency=low
 .
   * SECURITY UPDATE: denial of service via decompression bomb (LP: #533140)
     - debian/patches/02-CVE-2010-0205.patch: use new two-pass decompression
       method in pngrutil.c.
     - CVE-2010-0205
Checksums-Sha1: 
 d74ed91f0d3b784aac024e6c3f2db998a9dd0865 1291 libpng_1.2.42-1ubuntu2.dsc
 623f3a835a3c7f0409ef9cf0ee02ed86eda7da3f 17723 libpng_1.2.42-1ubuntu2.debian.tar.bz2
Checksums-Sha256: 
 9052aef7d7b324e259971005866554b625163d6725ea1ec433f8352a0e206705 1291 libpng_1.2.42-1ubuntu2.dsc
 96add7ffee2382113dce48b847a9b56b0b934d1e74f9f0aa79a4405c80d62451 17723 libpng_1.2.42-1ubuntu2.debian.tar.bz2
Files: 
 9563d627d61f5ef48ccf734795c395a5 1291 libs optional libpng_1.2.42-1ubuntu2.dsc
 ab4940dc837c88cc6c3351a3f19b3d76 17723 libs optional libpng_1.2.42-1ubuntu2.debian.tar.bz2
Original-Maintainer: Anibal Monsalve Salazar <anibal at debian.org>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkueV70ACgkQLMAs/0C4zNrD7wCeI9w2nZ4gKmYkN+OlLiRjfnrH
jAQAoIPD7km6Ngp3NemBISkHhyEaH3Ua
=xjJJ
-----END PGP SIGNATURE-----


More information about the Lucid-changes mailing list