| Author |
Message |
Monsie

Joined: 01 Dec 2011 Posts: 464 Location: Kamloops BC Canada
|
Posted: Sat 18 Feb 2012, 17:19 Post subject:
libpng security advisory |
|
Hi all,
This flaw in libpng was reported on February 15th. It involves an integer overflow which can be exploited through the browser if a hacker uses malformed images on a website and such images can also be sent through e-mail.
It appears there are a couple of approaches to fixing this problem. Mozilla has already issued a fix for Firefox 10 as announced in this article: http://www.internetnews.com/blog/skerner/mozilla-releases-firefox-10.0.2-for-png-flaw.html whereas Debian has issued an update for libpng http://www.debian.org/security/2012/dsa-2410 which in my thinking gets at the root of the problem, because it did not issue an update for its IceWeasel (Firefox) browser.
So, I am wondering to what extent this affects Puppy and whether Debian's libpng fix could be ported to Puppy.
Here is a screenshot from my Wary desktop which shows that libpng is used in a lot of places.
Monsie
| Description |
|

Download |
| Filename |
libpngsearch.jpg |
| Filesize |
168.51 KB |
| Downloaded |
195 Time(s) |
_________________ My username is pronounced: "mun-see". Derived from my surname, it was my nickname throughout high school.
|
|
Back to top
|
|
 |
Terryphi

Joined: 02 Jul 2008 Posts: 698 Location: West Wales, Britain.
|
Posted: Sun 19 Feb 2012, 06:27 Post subject:
|
|
Yes, /usr/lib/libpng12.so.0.44.0 needs replacing with the later version. Some versions may use libpng12.so.0.42.0 which also needs updating.
If you visit a malicious website which serves a specially crafted .png file ( or open such a file in an email attachment) it will crash your system. That seems to be all there is to it.
_________________ Opera browser SFS package for Precise, Slacko, Racy, Wary, Lucid, Quirky, etc available here 
|
|
Back to top
|
|
 |
Monsie

Joined: 01 Dec 2011 Posts: 464 Location: Kamloops BC Canada
|
Posted: Sun 19 Feb 2012, 15:03 Post subject:
libpng security advisory |
|
Thanks Terryphi for the additional information. This prompted me to do some more research, and I found the latest details at: http://www.libpng.org/pub/png/libpng.html as well as links for downloading the source code regarding the newest patch which if I understand the number system correctly would be libpng.1.2.47 This version was just released yesterday (Feb. 18th).
That said, I'm wondering about protocol. For releases such as Wary and Racy, is it up to Barry to compile the source code and release it, or can someone in the Puppy Community do so and submit it for Barry's approval?
Monsie
_________________ My username is pronounced: "mun-see". Derived from my surname, it was my nickname throughout high school.
|
|
Back to top
|
|
 |
01micko

Joined: 11 Oct 2008 Posts: 7018 Location: qld
|
Posted: Sun 19 Feb 2012, 16:15 Post subject:
|
|
The latest Slacko RC2 has both seamonkey-2.7.2 with the fix compiled against libpng-14.
_________________ keep the faith .. 
|
|
Back to top
|
|
 |
pemasu

Joined: 08 Jul 2009 Posts: 5167 Location: Finland
|
Posted: Sun 19 Feb 2012, 17:31 Post subject:
|
|
I just picked the security updated libpng from squeeze security-update page. It had same libpng version number as the one I had. So...there wont be any conflicts with other libs.
The build is Dpup Exprimo.
|
|
Back to top
|
|
 |
Semme
Joined: 07 Aug 2011 Posts: 2041 Location: World_Hub
|
Posted: Mon 20 Feb 2012, 07:35 Post subject:
|
|
More from Linux Security and H-Online..
|
|
Back to top
|
|
 |
|