libpng.so is vulnerable to denial of service (DoS). The attacker can input a malicious PNG file to the png_decompress_chunk
function, causing a heap buffer overflow that can crash the application.
code.google.com/p/chromium/issues/detail?id=112822
googlechromereleases.blogspot.com/2012/02/chrome-stable-update.html
lists.apple.com/archives/security-announce/2012/Sep/msg00003.html
lists.apple.com/archives/security-announce/2012/Sep/msg00004.html
lists.opensuse.org/opensuse-security-announce/2012-02/msg00020.html
lists.opensuse.org/opensuse-security-announce/2012-02/msg00023.html
secunia.com/advisories/48016
secunia.com/advisories/48110
secunia.com/advisories/49660
security.gentoo.org/glsa/glsa-201206-15.xml
support.apple.com/kb/HT5501
support.apple.com/kb/HT5503
bugzilla.redhat.com/show_bug.cgi?id=790737
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15032