Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Mageia 6: 2019-0126 Critical: Libpng Buffer Overflow Issue

mageia
Calendar Grey April 5, 2019
Dist Mageia Esm H88
Security notice for Mageia 6 concerning libpng patch that resolves the use-after-free vulnerability identified as CVE-2019-7317.
png_image_free in png.c in libpng 1.6.0 up to 1.6.36 had a use-after-free because png_image_free_function is called under png_safe_execute (CVE-2019-7317)

Summary

png_image_free in png.c in libpng 1.6.0 up to 1.6.36 had a use-after-free because png_image_free_function is called under png_safe_execute (CVE-2019-7317).

References

- https://bugs.mageia.org/show_bug.cgi?id=24353

- https://github.com/pnggroup/libpng/issues/275

- https://www.cve.org/CVERecord?id=CVE-2019-7317

Resolution

SRPMS

- 6/core/libpng-1.6.35-1.1.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 05 Apr 2019
URL: https://advisories.mageia.org/MGASA-2019-0126.html
Type: security
CVE: CVE-2019-7317

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here