[CLSA-2025:1766135952] libpng: Fix of CVE-2025-64505
Type:
security
Severity:
Moderate
Release date:
2025-12-19 10:09:12 UTC
Description:
- CVE-2025-64505: fix heap buffer over-read vulnerability in png_do_quantize function by validating palette_lookup array bounds
Updated packages:
  • libpng-1.5.13-8.el7.tuxcare.els1.i686.rpm
    sha:b59fea4fe4c73454da6f76b22a589bd2dcb1424f0006841708ad2240c4cd3bd8
  • libpng-1.5.13-8.el7.tuxcare.els1.x86_64.rpm
    sha:dbc53961f673494440814ffa6f44ab6bf9b843d40486ec8c50493dceaa5ee4cb
  • libpng-devel-1.5.13-8.el7.tuxcare.els1.i686.rpm
    sha:da4cdac9adb0db6b1fb118c0ef2b030807825901105de3bf9fd8224c587d1025
  • libpng-devel-1.5.13-8.el7.tuxcare.els1.x86_64.rpm
    sha:82161e894e28d2fc6390e8dbc11dea4c767bdf9284f7da9d25d06085ff8eb4e6
  • libpng-static-1.5.13-8.el7.tuxcare.els1.i686.rpm
    sha:8f60a147f5f1ca92644244919bb51c5b00a74e79bc1c142af9972a41e1e8fd3f
  • libpng-static-1.5.13-8.el7.tuxcare.els1.x86_64.rpm
    sha:0a2d9520edb2ba0054edc885e1616bd9281244f04a6f223ab3a1ac63a4b2cc73
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.