FlawAtlas
Search the atlas
SUSE-SU-2019:3060-2 Not scored

Security update for libpng16

This update for libpng16 fixes the following issues: Security issues fixed: - CVE-2019-7317: Fixed a use-after-free vulnerability, triggered when png_image_free() was called under png_safe_execute (bsc#1124211). - CVE-2017-12652: Fixed an Input Validation Error related to the length of chunks (bsc#1141493).

Exploit probability Not scored
Published March 3, 2020
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 5 libpng16
SUSE:Linux Enterprise Server 12 SP1-LTSS libpng16
SUSE:Linux Enterprise Server 12 SP2-BCL libpng16
SUSE:Linux Enterprise Server 12 SP2-LTSS libpng16
SUSE:Linux Enterprise Server 12 SP3-BCL libpng16
SUSE:Linux Enterprise Server 12 SP3-LTSS libpng16
SUSE:Linux Enterprise Server for SAP Applications 12 SP1 libpng16
SUSE:Linux Enterprise Server for SAP Applications 12 SP2 libpng16
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 libpng16
SUSE:OpenStack Cloud 7 libpng16
SUSE:OpenStack Cloud 8 libpng16

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2019:3060-2

This update for libpng16 fixes the following issues: Security issues fixed: - CVE-2019-7317: Fixed a use-after-free vulnerability, triggered when png_image_free() was called under png_safe_execute (bsc#1124211). - CVE-2017-12652: Fixed an Input Validation Error related to the length of chunks (bsc#1141493).

View original source

05 / REFERENCES

Further evidence