MGASA-2018-0468
Dashboard / Vulnerabilities / MGASA-2018-0468
Summary: Updated libpng(12) packages fix security vulnerability
Details: In libpng until version 1.6.35, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service. (CVE-2018-13785) This update fixes it, also providing the current maintenance releases in the 1.2 and 1.6 stable branches.
References: https://advisories.mageia.org/MGASA-2018-0468.html, https://bugs.mageia.org/show_bug.cgi?id=23307, https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-13785.html
Affected packages
Package
Name: libpng
Purl: pkg:rpm/mageia/libpng?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
