MGASA-2014-0075
Dashboard / Vulnerabilities / MGASA-2014-0075
Summary: Updated libpng and libpng12 packages fix security vulnerability
Details: The png_do_expand_palette function in libpng before 1.6.8 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a PLTE chunk of zero bytes or a NULL palette, related to pngrtran.c and pngset.c (CVE-2013-6954).
References: https://advisories.mageia.org/MGASA-2014-0075.html, https://bugs.mageia.org/show_bug.cgi?id=12747, https://lists.fedoraproject.org/pipermail/package-announce/2014-February/128098.html, https://lists.fedoraproject.org/pipermail/package-announce/2014-February/128099.html
Affected packages
Package
Name: libpng
Purl: pkg:rpm/mageia/libpng?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
