REDHAT-BUG-2418711: High severity libpng LIBPNG vulnerability
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the pngsRGBbase[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libpngto a version that resolves this vulnerability.Fixed in 1.6.52
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2418711?
The severity of REDHAT-BUG-2418711 is considered high due to the potential for out-of-bounds reads.
How do I fix REDHAT-BUG-2418711?
To fix REDHAT-BUG-2418711, update libpng to version 1.6.52 or later.
Which versions of libpng are affected by REDHAT-BUG-2418711?
Versions of libpng prior to 1.6.52 are affected by REDHAT-BUG-2418711.
What types of applications are impacted by REDHAT-BUG-2418711?
Applications that read, create, or manipulate PNG files using the vulnerable versions of libpng are impacted by REDHAT-BUG-2418711.
Is there a known exploit for REDHAT-BUG-2418711?
As of now, there are no publicly disclosed exploits specifically targeting REDHAT-BUG-2418711.