imlib2 before 1.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted PNM file.
lists.opensuse.org/opensuse-updates/2016-05/msg00076.html
www.debian.org/security/2016/dsa-3537
www.securityfocus.com/bid/90955
git.enlightenment.org/legacy/imlib2.git/commit/?h=v1.4.7&id=c21beaf1780cf3ca291735ae7d58a3dde63277a2
git.enlightenment.org/legacy/imlib2.git/tree/ChangeLog
security.gentoo.org/glsa/201611-12