[CLSA-2025:1766165929] libpng: Fix of CVE-2025-64505
Type:
security
Severity:
Moderate
Release date:
2025-12-19 17:38:53 UTC
Description:
- CVE-2025-64505: fix heap buffer over-read vulnerability in png_do_quantize function by validating palette_lookup array bounds
Updated packages:
  • libpng-1.5.13-8.el7.tuxcare.els1.i686.rpm
    sha:80cb9368d04f06edeb6ebc3320238375b6b0cb0b37a8140ea68cae2212d580fb
  • libpng-1.5.13-8.el7.tuxcare.els1.x86_64.rpm
    sha:7d6ff0e7c2eb1cf138afebe7a969504e8d57118f31167798d72396e7b1dbeba4
  • libpng-devel-1.5.13-8.el7.tuxcare.els1.i686.rpm
    sha:853a76f52b4a69d914adb7dabac142e739be851e421fdd06abdfec5f894a1556
  • libpng-devel-1.5.13-8.el7.tuxcare.els1.x86_64.rpm
    sha:ca52e4e0dc322fd08751d459984c22b29a45cbaa714e6051ee4aef7dbf519ace
  • libpng-static-1.5.13-8.el7.tuxcare.els1.i686.rpm
    sha:97577b10764d0f0316c682285a23ffdf476e569709f33bea9078b301b9c4e81b
  • libpng-static-1.5.13-8.el7.tuxcare.els1.x86_64.rpm
    sha:fa9d4c36be948f1a162a999c04d70e635c983bbcb3530ad9e3a3bc3bb911ce9f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.