About libpng vulnerability issue in png_user_version_check().
Issue
- According to the following libpng upstream site, libpng has a vulnerability issue in png_user_version_check().
- libpng Home Page
Vulnerability Warning
Virtually all libpng versions through 1.6.14, 1.5.19, 1.4.13, 1.2.51, and 1.0.61, respectively, have an out-of-bounds memory access
in png_user_version_check(). It is unclear whether this could lead to an actual exploit. The bug is fixed in versions 1.6.15,
1.5.20, etc., released on 20 November 2014.
- However, cve number is not assigned yet and it seems that redhat does not handle it, either.
- Could you please tell if this vulnerability issue affects libpng redhat shipped?
Environment
- Red Hat Enterprise Linux 5.10
- libpng-1.2.10-17.el5-8
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.
Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.
