The following defect(s) have been fixed in this cumulative patch for the Wind River libpng:
WIND00204141 Security Advisory - libpng - CVE-2010-0205
WIND00254766 Security Advisory - libpng - CVE-2011-0408
WIND00291617 Security Advisory - libpng - CVE-2011-2690
WIND00291620 Security Advisory - libpng - CVE-2011-2692
WIND00353043 Security Advisory - libpng - CVE-2011-3048
-------------------------------------------------------------------------------------
Change List:
/wrlinux/dist/libpng/Makefile
/wrlinux/dist/libpng/patches/libpng-fix-CVE-2011-0408.patch
/wrlinux/dist/libpng/patches/libpng-fix-CVE-2011-2690.patch
/wrlinux/dist/libpng/patches/libpng-fix-CVE-2011-2692.patch
/wrlinux/dist/libpng/patches/libpng-fix-CVE-2011-3048.patch
/wrlinux/dist/libpng/patches/patches.list
/wrlinux/dist/libpng/patches/libpng-1.2.15-CVE-2010-0205.patch
Requires Wind River Linux 2.0 Update Pack 4 (2.0.4) to be installed.
1. Unzip this patch under [install_dir]/updates
2. From the [install_dir]/updates directory, run the command "../maintenance/mtool/mtool_linux"
3. Follow the instructions for installing the point patch.
4. This is a source only patch so you will have to rebuild the libpng package.
This can be done by executing the command "make -C build libpng
.distclean"followed by "make -C build libpng.rebuild"
5. Run "make fs" next
6. Upload the kernel and rootfs into the target and boot it up
DATE: 04 Jul 2012
REVISION: Add file WRL_2_0_4-base-tgt-libpng-20120628-spin1.zip and includes fix to defect WIND00353043
DATE: 31 Aug 2011
REVISION: file WRL_2_0_4-base-tgt-libpng-20110224-spin1.zip replaced with WRL_2_0_4-base-tgt-libpng-20110829-spin1.zip and includes fix to defect WIND00291617
file WRL_2_0_4-base-tgt-libpng-20110829-spin1.zip replaced with WRL_2_0_4-base-tgt-libpng-20110829-spin2.zip and includes fix to defect WIND00291620
DATE: 02 Mar 2011
REVISION: file WRL_2_0_4-base-tgt-libpng-20100401-spin1.zip replaced with WRL_2_0_4-base-tgt-libpng-20110224-spin1.zip and includes fix to defect WIND00254766
DATE: 06 April 2010
REVISION: Add file WRL_2_0_4-base-tgt-libpng-20100401-spin1.zip and includes fix to defect WIND00204141