DSA-4435-1 libpng1.6 -- security update

Related Vulnerabilities: CVE-2019-7317  

A use-after-free vulnerability was discovered in the png_image_free() function in the libpng PNG library, which could lead to denial of service or potentially the execution of arbitrary code if a malformed image is processed. For the stable distribution (stretch), this problem has been fixed in version 1.6.28-1+deb9u1. We recommend that you upgrade your libpng1.6 packages. For the detailed security status of libpng1.6 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libpng1.6

Debian Security Advisory

DSA-4435-1 libpng1.6 -- security update

Date Reported:
27 Apr 2019
Affected Packages:
libpng1.6
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 921355.
In Mitre's CVE dictionary: CVE-2019-7317.
More information:

A use-after-free vulnerability was discovered in the png_image_free() function in the libpng PNG library, which could lead to denial of service or potentially the execution of arbitrary code if a malformed image is processed.

For the stable distribution (stretch), this problem has been fixed in version 1.6.28-1+deb9u1.

We recommend that you upgrade your libpng1.6 packages.

For the detailed security status of libpng1.6 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libpng1.6