REDHAT-BUG-608644: Low severity libp2p vulnerability
A memory leak was found in the way libpng processed malformed Portable Network Graphics (PNG) images with Physical Scale (sCAL) extension. A remote attacker could create a specially-crafted PNG image and trick the local user into opening it in an application, using the libpng library, leading to denial of service (relevant libpng-based application crash).
References: [1] http://www.libpng.org/pub/png/libpng.html
CVE Request: [2] http://www.openwall.com/lists/oss-security/2010/06/28/2
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-608644?
The severity of REDHAT-BUG-608644 is considered high due to the potential for remote exploitation through a crafted PNG image.
How do I fix REDHAT-BUG-608644?
To fix REDHAT-BUG-608644, update to the latest version of libpng that addresses the memory leak issue.
What are the potential impacts of REDHAT-BUG-608644?
The potential impacts of REDHAT-BUG-608644 include application crashes and possible arbitrary code execution if a user opens a malicious PNG file.
Which software is affected by REDHAT-BUG-608644?
REDHAT-BUG-608644 affects the libpng library used in applications that process PNG images.
Is there a way to mitigate the risk of REDHAT-BUG-608644?
Mitigation strategies for REDHAT-BUG-608644 include avoiding the opening of untrusted PNG files and applying the latest security updates for libpng.