Note: This is a public test instance of Red Hat Bugzilla. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback at bugzilla.redhat.com.

Bug 1282039

Summary: CVE-2015-8126 libpng10: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [fedora-all]
Product: [Fedora] Fedora Reporter: Paul Howarth <paul>
Component: libpng10Assignee: Paul Howarth <paul>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: medium    
Version: 23CC: paul
Target Milestone: ---Keywords: Reopened, Security, SecurityTracking
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: libpng10-1.0.64-1.fc23 libpng10-1.0.64-1.fc22 libpng10-1.0.64-1.fc21 libpng10-1.0.65-1.fc23 libpng10-1.0.65-1.fc22 Doc Type: Release Note
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-12-18 07:54:03 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Paul Howarth 2015-11-14 13:48:10 UTC
Tracking bug for affected Fedora releases 21 .. 23.

Comment 1 Fedora Update System 2015-11-14 13:54:51 UTC
libpng10-1.0.64-1.fc23 has been submitted as an update to Fedora 23. https://bodhi.fedoraproject.org/updates/FEDORA-2015-1d87313b7c

Comment 2 Fedora Update System 2015-11-14 13:56:07 UTC
libpng10-1.0.64-1.fc22 has been submitted as an update to Fedora 22. https://bodhi.fedoraproject.org/updates/FEDORA-2015-ec2ddd15d7

Comment 3 Fedora Update System 2015-11-14 13:58:32 UTC
libpng10-1.0.64-1.fc21 has been submitted as an update to Fedora 21. https://bodhi.fedoraproject.org/updates/FEDORA-2015-501493d853

Comment 4 Fedora Update System 2015-11-24 19:52:06 UTC
libpng10-1.0.64-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2015-11-24 22:24:29 UTC
libpng10-1.0.64-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2015-11-24 22:50:06 UTC
libpng10-1.0.64-1.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2015-12-04 12:19:39 UTC
libpng10-1.0.65-1.fc22 has been submitted as an update to Fedora 22. https://bodhi.fedoraproject.org/updates/FEDORA-2015-3461e976cb

Comment 8 Fedora Update System 2015-12-04 12:19:40 UTC
libpng10-1.0.65-1.fc23 has been submitted as an update to Fedora 23. https://bodhi.fedoraproject.org/updates/FEDORA-2015-8c475f7169

Comment 9 Fedora Update System 2015-12-04 16:50:49 UTC
libpng10-1.0.65-1.fc23 has been pushed to the Fedora 23 testing repository. If problems still persist, please make note of it in this bug report.
If you want to test the update, you can install it with
$ su -c 'dnf --enablerepo=updates-testing update libpng10'
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2015-8c475f7169

Comment 10 Fedora Update System 2015-12-04 17:20:20 UTC
libpng10-1.0.65-1.fc22 has been pushed to the Fedora 22 testing repository. If problems still persist, please make note of it in this bug report.
If you want to test the update, you can install it with
$ su -c 'dnf --enablerepo=updates-testing update libpng10'
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2015-3461e976cb

Comment 11 Fedora Update System 2015-12-18 07:53:50 UTC
libpng10-1.0.65-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.

Comment 12 Fedora Update System 2015-12-18 09:58:27 UTC
libpng10-1.0.65-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.