|Reported by:||Owned by:|
Spotted in an lwn report of security fixes by Slackware: libpng-1.6.27. Not showing in the normal link to sourceforge, but the external home page http://www.libpng.org/pub/png/libpng.html points to [prdownloads.sourceforge.net/libpng/libpng-1.6.27.tar.xz/download] which worked for me (whether it works when editing the book is, of course, a different matter).
From the external home page:
Virtually all libpng versions through 1.6.26, 1.5.27, 1.4.19, 1.2.56, and 1.0.66, respectively, have a null-pointer-dereference bug in png_set_text_2() when an image-editing application adds, removes, and re-adds text chunks to a PNG image. (This bug does not affect pure viewers, nor are there any known editors that could trigger it without interactive user input. It has been assigned ID CVE-2016-10087.) The vulnerability is fixed in versions 1.6.27, 1.5.28, 1.4.20, 1.2.57, and 1.0.67, released on 29 December 2016.