Please support VectorLinux!

Author Topic: libpng security update  (Read 2261 times)

wigums

  • Guest
libpng security update
« on: December 16, 2015, 07:07:28 am »
libpng has been updated for 7.1 and 7.2 to address security issues.
it can be found in the untested repo

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8126
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7981
« Last Edit: December 16, 2015, 07:27:43 am by wigums »

hata_ph

  • Packager
  • Vectorian
  • ****
  • Posts: 3286
  • -- Just being myself --
Re: libpng security update
« Reply #1 on: December 16, 2015, 07:55:50 pm »
Upgrading libpng-1.6.20 break few apps. Reinstall libpng-1.5.12 resolve the problem.

Quote
vector:/~/vl72
benreilly:$ terminal
Console=/usr/bin/xterm
Launching /usr/bin/xterm
/usr/bin/xterm: error while loading shared libraries: libpng15.so.15: cannot open shared object file: No such file or directory
vector:/~/vl72
benreilly:$ xterm
xterm: error while loading shared libraries: libpng15.so.15: cannot open shared object file: No such file or directory
vector:/~/vl72
benreilly:$

M0E-lnx

  • Administrator
  • Vectorian
  • *****
  • Posts: 3497
Re: libpng security update
« Reply #2 on: December 17, 2015, 04:49:38 am »
On 7.2, this should have been updated to 1.5.24, not the 1.6 series

hata_ph

  • Packager
  • Vectorian
  • ****
  • Posts: 3286
  • -- Just being myself --
Re: libpng security update
« Reply #3 on: December 17, 2015, 05:10:57 am »
I am building libpng-1.5.25 for VL 7.1 and 7.2.

M0E-lnx

  • Administrator
  • Vectorian
  • *****
  • Posts: 3497
Re: libpng security update
« Reply #4 on: December 17, 2015, 06:31:07 am »
It looks like we already had libpng 1.6.18 in 7.2, so after reading the CVE, we should have 1.6.20 in 7.2.  Vector 7.1 has to be kept @ 1.5.x, in which case the safe version seems to be 1.5.25

hata_ph

  • Packager
  • Vectorian
  • ****
  • Posts: 3286
  • -- Just being myself --
Re: libpng security update
« Reply #5 on: December 17, 2015, 04:40:53 pm »
Install libpng-1.2.25 in VL 7.1. No problem even after a restart...

roarde

  • Vectorian
  • ****
  • Posts: 778
  • it's enough
Re: libpng security update
« Reply #6 on: December 20, 2015, 12:33:38 pm »
On 7.1, I get the same good result as hata_ph.
Robert