Security Fix(es):
Off-by-one error in the bmprle4fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file, which triggers a heap-based buffer overflow.(CVE-2016-3982)
Heap-based buffer overflow in the bmpreadrows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file.(CVE-2016-3981)
{ "severity": "High" }
{ "x86_64": [ "optipng-debuginfo-0.7.7-1.oe1.x86_64.rpm", "optipng-debugsource-0.7.7-1.oe1.x86_64.rpm", "optipng-0.7.7-1.oe1.x86_64.rpm" ], "aarch64": [ "optipng-0.7.7-1.oe1.aarch64.rpm", "optipng-debugsource-0.7.7-1.oe1.aarch64.rpm", "optipng-debuginfo-0.7.7-1.oe1.aarch64.rpm" ], "src": [ "optipng-0.7.7-1.oe1.src.rpm" ] }