It was reported [1] that libpng 1.5.4 suffered from a flaw when encountering a malformed cHRM chunk in a PNG graphics file. libpng would perform a divide-by-zero, which would cause libpng, or any application linked to libpng, to crash. This flaw only affected libpng 1.5.4 where it was introduced, and is corrected in version 1.5.5. [2] [1] http://www.kb.cert.org/vuls/id/477046 [2] http://sourceforge.net/tracker/index.php?func=detail&aid=3406145&group_id=5624&atid=105624 Statement: Not vulnerable. This issue did not affect the versions of libpng as shipped with Red Hat Enterprise Linux 4, 5, or 6.
This does not affect anything we ship; we do not provide libpng 1.5.x in any product.