REDHAT-BUG-720608: Low severity libp2p vulnerability
It was found that in libpng, prior to 1.2.45, the error function received a NULL pointer, expressed erroneously as '\0', instead of the empty string "". This error was introduced in libpng-1.2.20, and pngdefaulterror() will crash in this case.
This was be fixed in libpng-1.5.4, libpng-1.4.8, libpng-1.2.45, and libpng-1.0.55.
Patch: http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commitdiff;h=9dad5e37aef295b4ef8dea39392b652deebc9261
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-720608?
The severity of REDHAT-BUG-720608 is considered high as it can lead to a crash in applications using the affected versions of libpng.
How do I fix REDHAT-BUG-720608?
To fix REDHAT-BUG-720608, upgrade to libpng version 1.5.4 or later.
What versions of libpng are affected by REDHAT-BUG-720608?
Versions of libpng prior to 1.2.45 and those between 1.2.20 and 1.5.4 are affected by REDHAT-BUG-720608.
What happens if I use an affected version of libpng in REDHAT-BUG-720608?
Using an affected version of libpng can cause the png_default_error() function to crash when a NULL pointer is passed.
Is there a known exploit for REDHAT-BUG-720608?
As of now, there is no publicly available exploit specifically targeting REDHAT-BUG-720608.