| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: libpng12-0 | Distribution: openSUSE Tumbleweed |
| Version: 1.2.59 | Vendor: openSUSE |
| Release: 6.2 | Build date: Tue Jul 14 08:07:26 2026 |
| Group: System/Libraries | Build host: reproducible |
| Size: 219450 | Source RPM: libpng12-1.2.59-6.2.src.rpm |
| Packager: https://bugs.opensuse.org | |
| Url: http://www.libpng.org/pub/png/libpng.html | |
| Summary: Library for the Portable Network Graphics Format (PNG) | |
libpng is the official reference library for the Portable Network Graphics format (PNG).
Zlib
* Tue Jul 14 2026 Petr Gajdos <pgajdos@suse.com>
- added patches
CVE-2026-25646: Heap buffer overflow vulnerability in png_set_dither/png_set_quantize [bsc#1258020]
* libpng12-CVE-2026-25646.patch
* Tue Apr 28 2026 Petr Gajdos <pgajdos@suse.com>
- added patches
CVE-2026-33416: use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` can lead to arbitrary code execution [bsc#1260754]
* libpng12-CVE-2026-33416.patch
CVE-2026-34757: Information disclosure and data corruption via use-after-free vulnerability [bsc#1261957]
* libpng12-CVE-2026-34757.patch
* Wed Dec 03 2025 Petr Gajdos <pgajdos@suse.com>
- security update
- modified patches
* libpng-1.2.51-CVE-2013-7353.patch (-p1)
* libpng-1.2.51-CVE-2013-7354.patch (-p1)
- added patches
CVE-2025-64505 [bsc#1254157], heap buffer over-read in `png_do_quantize` via malformed palette index
* libpng12-CVE-2025-64505.patch
* Fri Mar 01 2024 pgajdos@suse.com
- Use %autosetup macro. Allows to eliminate the usage of deprecated
%patchN
* Wed May 04 2022 Marcus Meissner <meissner@suse.com>
- switched to https url
* Wed Jul 17 2019 pgajdos@suse.com
- version update to 1.2.59
Added png_check_chunk_length() function, and check all chunks except
IDAT against the default 8MB limit; check IDAT against the maximum
size computed from IHDR parameters (Fixes CVE-2017-12652).
Initialize memory allocated by png_inflate to zero, using memset, to
stop an oss-fuzz "use of uninitialized value" detection in png_set_text_2()
due to truncated iTXt or zTXt chunk.
- fixes CVE-2017-12652 [bsc#1141493]
* Wed Jan 31 2018 pgajdos@suse.com
- check with -j1, be explicit
* Tue Jan 30 2018 jengelh@inai.de
- Fix SRPM group and grammar issues.
* Mon Jan 02 2017 pgajdos@suse.com
- updated to 1.2.57: fixes CVE-2016-10087
* Thu Dec 17 2015 pgajdos@suse.com
- updated to 1.2.56:
Fixed an out-of-range read in png_check_keyword() (Bug report from
Qixue Xiao, CVE-2015-8540).
Added keyword checks to pngset.c
/usr/lib64/libpng12.so.0 /usr/lib64/libpng12.so.0.59.0
Generated by rpm2html 1.8.1
Fabrice Bellet, Tue Aug 4 22:41:58 2026