{"id":"MGASA-2021-0115","summary":"Updated pngcheck packages fix security vulnerabilities","details":"This update fixes a buffer-overrun bug related to the MNG LOOP chunk\n(which gets noticed even in PNG files if the -s option is used).\n(RHBZ#1908559).\n\nIt also fixes a buffer overrun for certain invalid MNG PPLT chunk contents.\n(RHBZ#1907428).\n","modified":"2026-04-16T04:25:21.823932Z","published":"2021-03-05T16:15:59Z","references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0115.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=28331"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/XTD56567QSWLCTKBJNTCF6HB5GLJZCHX/"}],"affected":[{"package":{"name":"pngcheck","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/pngcheck?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.2-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0115.json"}},{"package":{"name":"pngcheck","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/pngcheck?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.2-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0115.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}