Comment 1 for bug 1960400

Revision history for this message
Andrew Aitchison (werdnakendal) wrote :

According to http://www.libpng.org/pub/png/apps/pngcheck.html v3.0.3 fixes a vulnerability:

Vulnerability Warning

pngcheck versions 3.0.2 and earlier have a divide-by-zero bug when zlib-decoding interlaced PNGs with extra data beyond what is required for the declared image dimensions. This bug is fixed in version 3.0.3, released on 25 April 2021. Again, while all known vulnerabilities are fixed in this version, the code is quite crufty, so it would be safest to assume there are still some problems hidden in there. As always, use at your own risk.