About libpng vulnerability issue in png_user_version_check().

Solution In Progress - Updated -

Issue

  • According to the following libpng upstream site, libpng has a vulnerability issue in png_user_version_check().
  • libpng Home Page
Vulnerability Warning
Virtually all libpng versions through 1.6.14, 1.5.19, 1.4.13, 1.2.51, and 1.0.61, respectively, have an out-of-bounds memory access
in png_user_version_check(). It is unclear whether this could lead to an actual exploit. The bug is fixed in versions 1.6.15,
1.5.20, etc., released on 20 November 2014.
  • However, cve number is not assigned yet and it seems that redhat does not handle it, either.
  • Could you please tell if this vulnerability issue affects libpng redhat shipped?

Environment

  • Red Hat Enterprise Linux 5.10
  • libpng-1.2.10-17.el5-8

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.