REDHAT-BUG-2416904: High severity libpng LIBPNG vulnerability
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, an out-of-bounds read vulnerability exists in pngimagereadcomposite when processing palette images with PNGFLAGOPTIMIZEALPHA enabled. The palette compositing code in pnginitreadtransformations incorrectly applies background compositing during premultiplication, violating the invariant component ≤ alpha × 257 required by the simplified PNG API. This issue has been patched in version 1.6.51.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libpngto a version that resolves this vulnerability.Fixed in 1.6.51
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2416904?
The severity of REDHAT-BUG-2416904 is considered critical due to the potential for exploitation leading to information disclosure.
How do I fix REDHAT-BUG-2416904?
To fix REDHAT-BUG-2416904, update the Libpng library to version 1.6.51 or later.
What versions are affected by REDHAT-BUG-2416904?
Versions of Libpng from 1.6.0 to before 1.6.51 are affected by REDHAT-BUG-2416904.
Can REDHAT-BUG-2416904 lead to data loss?
While REDHAT-BUG-2416904 primarily allows for information disclosure, it does not directly lead to data loss.
Is authentication required to exploit REDHAT-BUG-2416904?
No authentication is required to exploit REDHAT-BUG-2416904, making it a significant risk for applications using the affected versions.