pngcheck 3.0.3 published 2021

Bug #1960400 reported by Thees Ullmann
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
pngcheck (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Having discovered pngcheck lately, I suggest updating this package before the next Ubuntu LTS release. The envisaged pngcheck version for Ubuntu 22.04 seems to be 3.02 (https://packages.ubuntu.com/jammy/pngcheck), while a bug fix release 3.0.3 for pngcheck is available (see http://www.libpng.org/pub/png/apps/pngcheck.html).

Thank you!

tags: added: upgrade-software-version
Revision history for this message
Andrew Aitchison (werdnakendal) wrote :

According to http://www.libpng.org/pub/png/apps/pngcheck.html v3.0.3 fixes a vulnerability:

Vulnerability Warning

pngcheck versions 3.0.2 and earlier have a divide-by-zero bug when zlib-decoding interlaced PNGs with extra data beyond what is required for the declared image dimensions. This bug is fixed in version 3.0.3, released on 25 April 2021. Again, while all known vulnerabilities are fixed in this version, the code is quite crufty, so it would be safest to assume there are still some problems hidden in there. As always, use at your own risk.

Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in pngcheck (Ubuntu):
status: New → Confirmed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package pngcheck - 3.0.3-1build1

---------------
pngcheck (3.0.3-1build1) lunar; urgency=medium

  * Rebuild against new zlib 1.2.13.

 -- Gianfranco Costamagna <email address hidden> Mon, 23 Jan 2023 09:01:28 +0100

Changed in pngcheck (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.