REDHAT-BUG-720612: Medium severity libpng vulnerability
It was found that libpng read uninitialized memory when it encountered a sCAL chunk that is empty, and improperly handles a sCAL chunk that lacks the terminating zero between the two strings that it conveys.
This was fixed in libpng-1.5.4, libpng-1.4.8, libpng-1.2.45, and libpng-1.0.55.
Patch: http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commitdiff;h=61a2d8a2a7b03023e63eae9a3e64607aaaa6d339
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-720612?
The severity of REDHAT-BUG-720612 is categorized as a medium-risk vulnerability due to the potential for unintended information disclosure.
How do I fix REDHAT-BUG-720612?
To fix REDHAT-BUG-720612, you should upgrade to libpng versions 1.5.4, 1.4.8, 1.2.45, or 1.0.55, which contain the necessary patches.
What are the potential impacts of REDHAT-BUG-720612?
The potential impacts of REDHAT-BUG-720612 include the reading of uninitialized memory, which may lead to information leakage.
Which versions of libpng are affected by REDHAT-BUG-720612?
Affected versions of libpng include all versions prior to 1.5.4, 1.4.8, 1.2.45, and 1.0.55.
Is there a known exploit for REDHAT-BUG-720612?
As of now, there is no widely reported exploit for REDHAT-BUG-720612, but the vulnerability itself could be exploited in specific circumstances.