Change logs for libpng source package in Vivid

  • libpng (1.2.51-0ubuntu3.15.04.2) vivid-security; urgency=medium
    
      * SECURITY UPDATE: overflows in png_handle_zTXt(), png_handle_sPLT(),
        png_handle_pCAL(), and png_set_PLTE()
        - debian/patches/CVE-2015-8472.patch: check lengths in pngrutil.c,
          properly use info_ptr in pngset.c.
        - CVE-2015-8472
      * SECURITY UPDATE: out-of-range read in png_check_keyword()
        - debian/patches/CVE-2015-8540.patch: check key_len in pngwutil.c.
        - CVE-2015-8540
    
     -- Marc Deslauriers <email address hidden>  Fri, 18 Dec 2015 09:53:37 -0500
  • libpng (1.2.51-0ubuntu3.15.04.1) vivid-security; urgency=medium
    
      [ Andrew Starr-Bochicchio ]
      * SECURITY UPDATE: Multiple buffer overflows in the (1) png_set_PLTE
        and (2) png_get_PLTE (LP: #1516592).
        - debian/patches/CVE-2015-8126.diff: Prevent writing over-length
          PLTE chunk and silently truncate over-length PLTE chunk while reading.
          Backported from upstream patch.
        - CVE-2015-8126
    
      [ Marc Deslauriers ]
      * SECURITY UPDATE: out of bounds read in png_set_tIME
        - debian/patches/CVE-2015-7981.patch: check bounds in png.c and
          pngset.c.
        - CVE-2015-7981
    
     -- Marc Deslauriers <email address hidden>  Thu, 19 Nov 2015 07:59:38 -0500
  • libpng (1.2.51-0ubuntu3) utopic; urgency=medium
    
      * No-change rebuild to get debug symbols on all architectures.
     -- Brian Murray <email address hidden>   Tue, 21 Oct 2014 11:29:36 -0700