Advisories ยป MGASA-2014-0075

Updated libpng and libpng12 packages fix security vulnerability

Publication date: 16 Feb 2014
Type: security
Affected Mageia releases : 3
CVE: CVE-2013-6954

Description

The png_do_expand_palette function in libpng before 1.6.8 allows remote
attackers to cause a denial of service (NULL pointer dereference and
application crash) via a PLTE chunk of zero bytes or a NULL palette, related
to pngrtran.c and pngset.c (CVE-2013-6954).
                

References

SRPMS

3/core