Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT. https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Why was this filed? The pngcheck software is hosted at www.libpng.org and processes PNG files. It otherwise has no connection to libpng. It does not link libpng, it does not bundle libpng, and there is nothing in the spec file or source archive that ought to suggest otherwise.