Bug 1141493 (CVE-2017-12652) - VUL-1: CVE-2017-12652: libpng,libpng12,libpng15,libpng12-0,libpng16: libpng before 1.6.32 does not properly check the length of chunks against the user limit.
Summary: VUL-1: CVE-2017-12652: libpng,libpng12,libpng15,libpng12-0,libpng16: libpng b...
Status: RESOLVED FIXED
Alias: CVE-2017-12652
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Deadline: 2019-10-01
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/236838/
Whiteboard: maint:released:sle10-sp3:64341 CVSSv3...
Keywords:
Depends on:
Blocks:
 
Reported: 2019-07-15 12:14 UTC by Wolfgang Frisch
Modified: 2024-05-06 13:08 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 4 Petr Gajdos 2019-07-17 12:41:33 UTC
   15/libpng16:   version 1.6.34, already fixed
   12/libpng16:   png_check_chunk_length() will be added
   12/libpng15:   png_check_chunk_length() will be added
   12/libpng12:   png_check_chunk_length() will be added
   11/libpng12-0: png_check_chunk_length() will be added
10sp3/libpng:     png_check_chunk_length() will be added
Comment 5 Petr Gajdos 2019-07-17 13:04:23 UTC
I believe all fixed.
Comment 7 Swamp Workflow Management 2019-09-03 13:57:50 UTC
An update workflow for this issue was started.
This issue was rated as low.
Please submit fixed packages until 2019-10-01.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/64340
Comment 8 Swamp Workflow Management 2019-11-25 20:16:45 UTC
SUSE-SU-2019:3060-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1124211,1141493
CVE References: CVE-2017-12652,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    libpng16-1.6.8-15.5.2
SUSE Linux Enterprise Software Development Kit 12-SP4 (src):    libpng16-1.6.8-15.5.2
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    libpng16-1.6.8-15.5.2
SUSE Linux Enterprise Server 12-SP5 (src):    libpng16-1.6.8-15.5.2
SUSE Linux Enterprise Server 12-SP4 (src):    libpng16-1.6.8-15.5.2
SUSE Linux Enterprise Desktop 12-SP4 (src):    libpng16-1.6.8-15.5.2
SUSE CaaS Platform 3.0 (src):    libpng16-1.6.8-15.5.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Robert Snow 2020-02-25 20:37:59 UTC
This patch appears to have made it into SLES 12 sp3 LTSS for x86_64.  But does not appear in the channel for 12 sp3 for ppc64le.  Is this in the works or do I need to make an L3 request for this to happen?
Comment 10 Robert Snow 2020-02-26 19:47:47 UTC
Correction:  The customer SLES 12 sp3 for SAP applications on ppc64le.  As mentioned this patch is in the x86_64 update channel, but not in the ppc64le channel.  Do I need to open a new bug/l3?
Comment 11 Swamp Workflow Management 2020-03-03 14:14:14 UTC
SUSE-SU-2019:3060-2: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1124211,1141493
CVE References: CVE-2017-12652,CVE-2019-7317
Sources used:
SUSE OpenStack Cloud 8 (src):    libpng16-1.6.8-15.5.2
SUSE OpenStack Cloud 7 (src):    libpng16-1.6.8-15.5.2
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    libpng16-1.6.8-15.5.2
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    libpng16-1.6.8-15.5.2
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    libpng16-1.6.8-15.5.2
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    libpng16-1.6.8-15.5.2
SUSE Linux Enterprise Server 12-SP3-BCL (src):    libpng16-1.6.8-15.5.2
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    libpng16-1.6.8-15.5.2
SUSE Linux Enterprise Server 12-SP2-BCL (src):    libpng16-1.6.8-15.5.2
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    libpng16-1.6.8-15.5.2
SUSE Enterprise Storage 5 (src):    libpng16-1.6.8-15.5.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Swamp Workflow Management 2020-04-03 13:31:51 UTC
SUSE-SU-2020:0911-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1141493
CVE References: CVE-2017-12652
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    libpng12-1.2.50-20.3.2
SUSE Linux Enterprise Software Development Kit 12-SP4 (src):    libpng12-1.2.50-20.3.2
SUSE Linux Enterprise Server 12-SP5 (src):    libpng12-1.2.50-20.3.2
SUSE Linux Enterprise Server 12-SP4 (src):    libpng12-1.2.50-20.3.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Maintenance Automation 2023-09-27 12:30:11 UTC
SUSE-SU-2023:3799-1: An update that solves one vulnerability can now be installed.

Category: security (moderate)
Bug References: 1141493
CVE References: CVE-2017-12652
Sources used:
SUSE Linux Enterprise High Performance Computing 12 SP5 (src): libpng15-1.5.22-10.4.1
SUSE Linux Enterprise Server 12 SP5 (src): libpng15-1.5.22-10.4.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src): libpng15-1.5.22-10.4.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 14 Thomas Leroy 2024-05-06 13:08:52 UTC
All done, closing.