Количество 26
Количество 26
RLSA-2026:0241
Important: libpng security update
RLSA-2026:0238
Important: libpng security update
RLSA-2026:0237
Important: libpng security update
ELSA-2026-0241
ELSA-2026-0241: libpng security update (IMPORTANT)
ELSA-2026-0238
ELSA-2026-0238: libpng security update (IMPORTANT)
ELSA-2026-0237
ELSA-2026-0237: libpng security update (IMPORTANT)
ELSA-2026-0125
ELSA-2026-0125: mingw-libpng security update (IMPORTANT)
openSUSE-SU-2026:20017-1
Security update for libpng16
SUSE-SU-2025:4494-1
Security update for libpng16
SUSE-SU-2025:4436-1
Security update for libpng16
SUSE-SU-2025:4533-1
Security update for libpng16
CVE-2025-64720
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, an out-of-bounds read vulnerability exists in png_image_read_composite when processing palette images with PNG_FLAG_OPTIMIZE_ALPHA enabled. The palette compositing code in png_init_read_transformations incorrectly applies background compositing during premultiplication, violating the invariant component ≤ alpha × 257 required by the simplified PNG API. This issue has been patched in version 1.6.51.
CVE-2025-64720
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, an out-of-bounds read vulnerability exists in png_image_read_composite when processing palette images with PNG_FLAG_OPTIMIZE_ALPHA enabled. The palette compositing code in png_init_read_transformations incorrectly applies background compositing during premultiplication, violating the invariant component ≤ alpha × 257 required by the simplified PNG API. This issue has been patched in version 1.6.51.
CVE-2025-64720
LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication
CVE-2025-64720
LIBPNG is a reference library for use in applications that read, creat ...
CVE-2025-66293
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.
CVE-2025-66293
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.
CVE-2025-66293
LIBPNG has an out-of-bounds read in png_image_read_composite
CVE-2025-66293
LIBPNG is a reference library for use in applications that read, creat ...
CVE-2025-65018
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, there is a heap buffer overflow vulnerability in the libpng simplified API function png_image_finish_read when processing 16-bit interlaced PNGs with 8-bit output format. Attacker-crafted interlaced PNG files cause heap writes beyond allocated buffer bounds. This issue has been patched in version 1.6.51.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:0241 Important: libpng security update | 26 дней назад | |||
RLSA-2026:0238 Important: libpng security update | 26 дней назад | |||
RLSA-2026:0237 Important: libpng security update | 26 дней назад | |||
ELSA-2026-0241 ELSA-2026-0241: libpng security update (IMPORTANT) | 28 дней назад | |||
ELSA-2026-0238 ELSA-2026-0238: libpng security update (IMPORTANT) | 28 дней назад | |||
ELSA-2026-0237 ELSA-2026-0237: libpng security update (IMPORTANT) | 28 дней назад | |||
ELSA-2026-0125 ELSA-2026-0125: mingw-libpng security update (IMPORTANT) | 28 дней назад | |||
openSUSE-SU-2026:20017-1 Security update for libpng16 | 23 дня назад | |||
SUSE-SU-2025:4494-1 Security update for libpng16 | около 2 месяцев назад | |||
SUSE-SU-2025:4436-1 Security update for libpng16 | около 2 месяцев назад | |||
SUSE-SU-2025:4533-1 Security update for libpng16 | около 1 месяца назад | |||
CVE-2025-64720 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, an out-of-bounds read vulnerability exists in png_image_read_composite when processing palette images with PNG_FLAG_OPTIMIZE_ALPHA enabled. The palette compositing code in png_init_read_transformations incorrectly applies background compositing during premultiplication, violating the invariant component ≤ alpha × 257 required by the simplified PNG API. This issue has been patched in version 1.6.51. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2025-64720 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, an out-of-bounds read vulnerability exists in png_image_read_composite when processing palette images with PNG_FLAG_OPTIMIZE_ALPHA enabled. The palette compositing code in png_init_read_transformations incorrectly applies background compositing during premultiplication, violating the invariant component ≤ alpha × 257 required by the simplified PNG API. This issue has been patched in version 1.6.51. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2025-64720 LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2025-64720 LIBPNG is a reference library for use in applications that read, creat ... | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2025-66293 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2025-66293 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2025-66293 LIBPNG has an out-of-bounds read in png_image_read_composite | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2025-66293 LIBPNG is a reference library for use in applications that read, creat ... | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2025-65018 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, there is a heap buffer overflow vulnerability in the libpng simplified API function png_image_finish_read when processing 16-bit interlaced PNGs with 8-bit output format. Attacker-crafted interlaced PNG files cause heap writes beyond allocated buffer bounds. This issue has been patched in version 1.6.51. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу