Advisories ยป MGASA-2014-0076

Updated libpng12 package fixes security vulnerability

Publication date: 16 Feb 2014
Modification date: 16 Feb 2014
Type: security
Affected Mageia releases : 4
CVE: CVE-2013-6954

Description

The png_do_expand_palette function in libpng before 1.6.8 allows remote
attackers to cause a denial of service (NULL pointer dereference and
application crash) via a PLTE chunk of zero bytes or a NULL palette, related
to pngrtran.c and pngset.c (CVE-2013-6954).
                

References

SRPMS

4/core