REDHAT-BUG-2043393: Medium severity libp2p vulnerability
A vulnerability was reported in Libpng where the input buffer might not have the same length as the pre-defined value hardcoded in the pngimage so that the index is out of bound in the later loop.
References: https://github.com/glennrp/libpng/issues/302
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2043393?
The severity of REDHAT-BUG-2043393 is categorized as moderate due to potential out-of-bounds access.
How do I fix REDHAT-BUG-2043393?
To fix REDHAT-BUG-2043393, update to the latest version of Libpng that addresses this vulnerability.
What are the potential impacts of REDHAT-BUG-2043393?
The potential impacts of REDHAT-BUG-2043393 include crashes and possible arbitrary code execution due to out-of-bounds memory access.
Which versions of Libpng are affected by REDHAT-BUG-2043393?
All versions of Libpng prior to the fixed release addressing REDHAT-BUG-2043393 are affected.
Is there any workaround for REDHAT-BUG-2043393?
Currently, the best workaround for REDHAT-BUG-2043393 is to avoid using vulnerable versions of Libpng until an update is applied.