REDHAT-BUG-1672409: Use After Free
A vulnerability was found in libpng 1.6.36. The function pngimagefree in png.c has a use-after-free because pngimagefreefunction is called under pngsafeexecute.
References: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12803 https://github.com/glennrp/libpng/issues/275
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1672409?
The severity of REDHAT-BUG-1672409 is considered high due to the use-after-free vulnerability in libpng.
How do I fix REDHAT-BUG-1672409?
To fix REDHAT-BUG-1672409, you should update to the latest version of libpng that addresses this use-after-free issue.
What versions of libpng are affected by REDHAT-BUG-1672409?
REDHAT-BUG-1672409 affects libpng version 1.6.36 and potentially earlier versions.
What applications might be impacted by REDHAT-BUG-1672409?
Applications that utilize libpng for PNG image processing may be impacted by REDHAT-BUG-1672409.
Is there a workaround for REDHAT-BUG-1672409?
Currently, there are no known effective workarounds for REDHAT-BUG-1672409 other than upgrading libpng.