[CLSA-2026:1788175296] libpng: Fix of CVE-2016-10087
Type:
security
Severity:
Important
Release date:
2026-08-31 11:21:47 UTC
Description:
- CVE-2016-10087: reset info_ptr->max_text when png_free_data() releases the text array, so a later png_set_text_2() reallocates instead of writing through the freed pointer (NULL pointer dereference).
CVEs fixed:
Updated packages:
  • libpng-1.5.13-8.amzn2.0.9.tuxcare.els1.i686.rpm
    sha:ac4dd87798b0b511a0f7d0d7fe9a3ec0dc24c95cc08431099c1f0b508f51a45d
  • libpng-1.5.13-8.amzn2.0.9.tuxcare.els1.x86_64.rpm
    sha:bb1a54929455f40bccd5a4d32dc4688c832b0d6a65cec8b0f18f4c06457f3d7b
  • libpng-devel-1.5.13-8.amzn2.0.9.tuxcare.els1.x86_64.rpm
    sha:a9483ae73b5d6842cbd62b3834ac5c7dcbda8b21edb5a8aa723c05fe68fabee1
  • libpng-static-1.5.13-8.amzn2.0.9.tuxcare.els1.x86_64.rpm
    sha:36470fd2c7be9909c3d5c653b2efe8ced0dd198b72fe9f5459533a386b4c92df
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.