Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian: DSA-4435-1 Moderate: libpng Use-After-Free Denial of Service

debian
Calendar Grey April 27, 2019
Debian Logo
This patch fixes a serious use-after-free vulnerability in the libpng library that may lead to denial of service or arbitrary code execution risks.
A use-after-free vulnerability was discovered in the png_image_free() function in the libpng PNG library, which could lead to denial of service or potentially the execution of arbi...

Summary

For the stable distribution (stretch), this problem has been fixed in
version 1.6.28-1+deb9u1.

We recommend that you upgrade your libpng1.6 packages.

For the detailed security status of libpng1.6 please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libpng1.6

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Package: libpng1.6
CVE ID: CVE-2019-7317

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here