Opened 6 months ago
Closed 6 months ago
#23038 closed enhancement (fixed)
libpng-1.6.56
| Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | high | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (3)
comment:1 by , 6 months ago
| Priority: | normal → high |
|---|
comment:2 by , 6 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 6 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at ee4e9567de87f3fdd4931fbf5b13a344cfbb7e84
SA-13.0-016 issued
Note:
See TracTickets
for help on using tickets.

Another security release, and just like other ones recently, it's quite serious.
CVE-2026-33416 has a working exploit that explicitly causes remote code execution on glibc-based systems. The triggering PNG file is 100% valid too...