Package "libpng-tools"
| Name: |
libpng-tools
|
Description: |
PNG library - tools (version 1.6)
|
| Latest version: |
1.6.50-1ubuntu0.3 |
| Release: |
questing (25.10) |
| Level: |
security |
| Repository: |
main |
| Head package: |
libpng1.6 |
| Homepage: |
http://libpng.org/pub/png/libpng.html |
Links
Download "libpng-tools"
Other versions of "libpng-tools" in Questing
Changelog
|
libpng1.6 (1.6.50-1ubuntu0.3) questing-security; urgency=medium
* SECURITY UPDATE: OOB in png_image_read_composite
- debian/patches/CVE-2025-66293-1.patch: validate component size in
pngread.c.
- debian/patches/CVE-2025-66293-2.patch: improve fix in pngread.c.
- CVE-2025-66293
* SECURITY UPDATE: Heap buffer over-read in png_image_read_direct_scaled
- debian/patches/CVE-2026-22695.patch: fix memcpy size in pngread.c.
- CVE-2026-22695
* SECURITY UPDATE: Integer truncation causing heap buffer over-read
- debian/patches/CVE-2026-22801.patch: remove incorrect truncation
casts in CMakeLists.txt, contrib/libtests/pngstest.c, pngwrite.c,
tests/pngstest-large-stride.
- CVE-2026-22801
-- Marc Deslauriers <email address hidden> Mon, 12 Jan 2026 13:10:10 -0500
|
| Source diff to previous version |
| CVE-2025-66293 |
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to |
| CVE-2026-22695 |
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6. |
| CVE-2026-22801 |
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6. |
|
|
libpng1.6 (1.6.50-1ubuntu0.1) questing-security; urgency=medium
* SECURITY UPDATE: buffer overflow issue
- debian/patches/CVE-2025-64505.patch: Fix a buffer overflow in
png_do_quantize
- debian/patches/CVE-2025-64506.patch: Fix a heap buffer overflow in
png_write_image_8bit
- debian/patches/CVE-2025-64720.patch: Fix a buffer overflow in
png_init_read_transformations
- debian/patches/CVE-2025-65018.patch: Fix a heap buffer overflow in
png_image_finish_read
- CVE-2025-64505
- CVE-2025-64506
- CVE-2025-64720
- CVE-2025-65018
-- Nishit Majithia <email address hidden> Tue, 09 Dec 2025 17:38:32 +0530
|
| CVE-2025-64505 |
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to |
| CVE-2025-64506 |
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From vers |
| CVE-2025-64720 |
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From vers |
| CVE-2025-65018 |
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From vers |
|
About
-
Send Feedback to @ubuntu_updates