[Bluewhite64 Linux Security] libpng [BW64SA:20090622-01]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[Bluewhite64 Linux Security] libpng [BW64SA:20090622-01]

New libpng packages are available for Bluewhite64 Linux 11.0, 12.0,
12.1 and 12.2 to fix a security issue.

Jeff Phillips discovered an uninitialized-memory-read bug affecting interlaced
images that may have security implications.


More details about this issue may be found in the Common
Vulnerabilities and Exposures (CVE) database:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2042


Here are the details from the Bluewhite64 Linux 12.2 ChangeLog:
- ----------------------------------------------------------------
PATCHES/packages/libpng-1.2.37-x86_64-1.tgz: Upgraded.
This update fixes a possible security issue. Jeff Phillips discovered an
uninitialized-memory-read bug affecting interlaced images that may have
security implications.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2042
[*** Security fix ***]



Download the new packages from:
- --------------------------------
For Bluewhite64 Linux 11.0:
http://data.bluewhite64.com/bluewhite64-11.0/patches/packages/libpng-1.2.37-x86_64-1.tgz

For Bluewhite64 Linux 12.0:
http://data.bluewhite64.com/bluewhite64-12.0/patches/packages/libpng-1.2.37-x86_64-1.tgz

For Bluewhite64 Linux 12.1:
http://data.bluewhite64.com/bluewhite64-12.1/patches/packages/libpng-1.2.37-x86_64-1.tgz

For Bluewhite64 Linux 12.2:
http://data.bluewhite64.com/bluewhite64-12.2/patches/packages/libpng-1.2.37-x86_64-1.tgz


Also, please see the "Get Bluewhite64" section on http://www.bluewhite64.com for
additional mirror sites near you.


MD5 signatures:
- ----------------
Bluewhite64 11.0 package:
f2b52fd1792f4b5e2adadb16c4dfb03f libpng-1.2.37-x86_64-1.tgz

Bluewhite64 12.0 package:
46797077498e531079e929d2e140e45e libpng-1.2.37-x86_64-1.tgz

Bluewhite64 12.1 package:
d4210e4cf548e2579500f51b0ffce31b libpng-1.2.37-x86_64-1.tgz

Bluewhite64 12.2 package:
e7550e078d6fd51f698b0e430f2cee1d libpng-1.2.37-x86_64-1.tgz



Installation instructions:
- ----------------------------
Upgrade the package as root:
# upgradepkg libpng-1.2.37-x86_64-1.tgz



- ---
Bluewhite64 Linux Security Team
http://bluewhite64.com/gpg-key

security©bluewhite64.com



- ------------------------------------------------------
To leave the bluewhite64-security mailing list:
Send a blank email to

bluewhite64-security-unsubscribe©bluewhite64.com

You will get a confirmation message back containing
instructions to complete the process.

Please do not reply to this email address.
- ------------------------------------------------------



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAko/6cQACgkQpTOsxuDdlY5GYwCcD0GNMUrBLsF5kA9T3vsBY5TB
SV8An2kQPE0O20s+1x1oBLm7I4YO/CZZ
=az1i
-----END PGP SIGNATURE-----