Bug 125934

Summary: CAN-2002-1363 libpng miscalculation
Product: Red Hat Enterprise Linux 3 Reporter: Mark J. Cox <mjc>
Component: libpngAssignee: Matthias Clasen <mclasen>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 3.0Keywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2004-06-18 13:10:45 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Comment 1 Mark J. Cox 2004-06-14 11:58:22 UTC
Jesse Keating noticed that CAN-2002-1363 was not included in Red Hat
Linux packages since 9.0 - which therefore affects RHEL3, FC1, and FC2
packages.



Comment 2 Mark J. Cox 2004-06-18 13:10:45 UTC
Pushed RHSA-2004:249

Comment 3 Robert Scheck 2004-06-18 13:35:12 UTC
At current, there are no updated (or testing) packages for FC1 and FC2 
available, which are also affected by the vulnerability.

The patch from RHEL3 also applies to FC1, FC2 and Fedora Development's
libpng.

Comment 4 Mark J. Cox 2004-06-18 13:38:22 UTC
Updates for FC should be out later today.