[GLSA-201908-02] libpng: Multiple vulnerabilities

Severity Normal
Affected Packages 1
Unaffected Packages 1
CVEs 3

Multiple vulnerabilities have been found in libpng, the worst of which could result in a Denial of Service condition.

Background
libpng is a standard library used to process PNG (Portable Network
Graphics) images. It is used by several programs, including web browsers
and potentially server processes.

Description
Multiple vulnerabilities have been discovered in libpng. Please review
the CVE identifiers referenced below for details.

Impact
A remote attacker, by enticing a user to process a specially crafted PNG
file, could cause a Denial of Service condition.

Workaround
There is no known workaround at this time.

Resolution
All libpng users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/libpng-1.6.37"

Package Affected Version
pkg:ebuild/media-libs/libpng?distro=gentoo < 1.6.37
Package Unaffected Version
pkg:ebuild/media-libs/libpng?distro=gentoo >= 1.6.37
Source # ID Name URL
CVE CVE-2018-14048 CVE-2018-14048 https://nvd.nist.gov/vuln/detail/CVE-2018-14048
CVE CVE-2018-14550 CVE-2018-14550 https://nvd.nist.gov/vuln/detail/CVE-2018-14550
CVE CVE-2019-7317 CVE-2019-7317 https://nvd.nist.gov/vuln/detail/CVE-2019-7317
Bugzilla 683366 Bugzilla #683366 https://bugs.gentoo.org/show_bug.cgi?id=683366
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/media-libs/libpng?distro=gentoo media-libs libpng < 1.6.37 gentoo
Unaffected pkg:ebuild/media-libs/libpng?distro=gentoo media-libs libpng >= 1.6.37 gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...