REDHAT-BUG-1276416: Low severity libp2p vulnerability
Published Oct 29, 2015
·Updated
An out-of-bounds read in pngconverttorfc1123 in png.c was found.
Upstream bug:
http://sourceforge.net/p/libpng/bugs/241/
Upstream patch:
http://sourceforge.net/p/libpng/code/ci/fbf0f024346ca0a4ffc64b082a95c6b6bb6d29c4/
CVE assignment:
http://seclists.org/oss-sec/2015/q4/161
Affected Software
1 affected component
libpng LIBPNG
Event History
Oct 29, 2015
Data Sourced
via Red Hat·03:59 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1276416?
REDHAT-BUG-1276416 is classified as a moderate severity vulnerability due to the potential for out-of-bounds read.
2
How do I fix REDHAT-BUG-1276416?
To fix REDHAT-BUG-1276416, ensure you upgrade to the latest patched version of Libpng.
3
What is the nature of the vulnerability in REDHAT-BUG-1276416?
The vulnerability in REDHAT-BUG-1276416 involves an out-of-bounds read in the png_convert_to_rfc1123 function in png.c.
4
Who is affected by REDHAT-BUG-1276416?
REDHAT-BUG-1276416 affects users of Libpng and applications dependent on it.
5
When was REDHAT-BUG-1276416 reported?
REDHAT-BUG-1276416 was reported as an upstream bug on Sourceforge.