Lucene search

K
redhatRedHatRHSA-2012:0317
HistoryFeb 20, 2012 - 12:00 a.m.

(RHSA-2012:0317) Important: libpng security update

2012-02-2000:00:00
access.redhat.com
44

0.832 High

EPSS

Percentile

98.5%

The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A heap-based buffer overflow flaw was found in libpng. An attacker could
create a specially-crafted PNG image that, when opened, could cause an
application using libpng to crash or, possibly, execute arbitrary code with
the privileges of the user running the application. (CVE-2011-3026)

Users of libpng and libpng10 should upgrade to these updated packages,
which contain a backported patch to correct this issue. All running
applications using libpng or libpng10 must be restarted for the update to
take effect.