The vendor explicitly identifies these products or versions as containing the fix.
- libpng-main@aarch64 as a component of Red Hat Hardened Images
- libpng-main@src as a component of Red Hat Hardened Images
- libpng-main@x86_64 as a component of Red Hat Hardened Images
- Summary
- A flaw was found in libpng. A local attacker could exploit this vulnerability by manipulating the width/height arguments in the `do_pnm2png` function of the `pnm2png` component. This manipulation causes a heap-based buffer overflow, which could lead to information disclosure and denial of service (DoS).
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
