About libpng vulnerability issue in png_user_version_check().
Issue
- According to the following libpng upstream site, libpng has a vulnerability issue in png_user_version_check().
- libpng Home Page
Vulnerability Warning
Virtually all libpng versions through 1.6.14, 1.5.19, 1.4.13, 1.2.51, and 1.0.61, respectively, have an out-of-bounds memory access
in png_user_version_check(). It is unclear whether this could lead to an actual exploit. The bug is fixed in versions 1.6.15,
1.5.20, etc., released on 20 November 2014.
- However, cve number is not assigned yet and it seems that redhat does not handle it, either.
- Could you please tell if this vulnerability issue affects libpng redhat shipped?
Environment
- Red Hat Enterprise Linux 5.10
- libpng-1.2.10-17.el5-8
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.