Red Hat Bugzilla – Bug 211705
CVE-2006-3334, CVE-2006-5793 libpng 1.2.13 is out there
Last modified: 2013-07-02 23:11:26 EDT
Description of problem:
libpng 1.2.12 has been out there since 2006-06-27 and contains, together with
2.6.11 several fixes for various problems, among others at least one possible
(from the release notes)
Fix potential buffer overrun in chunk error processing.
Fix 1 potential overflow and 1 out-of-bounds read. Fix some bugs in makefiles.
APPLY PATCH to fix another potential overflow (see KNOWNBUGS1)
Version-Release number of selected component (if applicable):
2.6.13 is out by now and fixes again a security flaw:
This affects also fc6
(In reply to comment #1)
> 2.6.13 is out by now and fixes again a security flaw:
I mean 1.2.13
There are no known security issues in the libpng shipped in Fedora. The two CVE
ids in the summary are not considered security issues but simply bugs. We track
all known CVE ids related to fedora core here:
If there are any CVE ids not mentioned in those files, please open bugs as
libpng is updated to 1.2.16 for Fedora 7. As Josh notes, we don't currently see
a necessity to back-patch this.