Description: Tavis Ormandy has reported a vulnerability in libpng, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an out-of-bounds read error in the "png_set_sPLT()" function in pngset.c. This can be exploited by tricking an application using the library to process a specially crafted PNG file.
The vulnerability is reported in version 1.2.12. Other versions may also be affected.
Solution: Update to version 1.2.13.
Provided and/or discovered by: Tavis Ormandy, Gentoo Linux Security Auditing Team.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.