A global buffer overflow (out-of-bounds read) was discovered in pngcheck-2.4.0 and before in pngcheck() function in pngcheck.c via a crafted png file. Fixed in pngcheck v3.0.0 (upstream). https://bugzilla.redhat.com/show_bug.cgi?id=1905775 (original report) http://www.libpng.org/pub/png/apps/pngcheck.html
Created pngcheck tracking bugs for this issue: Affects: epel-all [bug 2155526]
This patch was backported into pngcheck 2.4 in EPEL8/7 at the time. https://bugzilla.redhat.com/show_bug.cgi?id=1905775#c13