libpng 1.6.51 Released with Security Fixes for Four Buffer Overflow Vulnerabilities
By
ledoge
The kind of bagel that ruins lesser bagels for you.
Summary
libpng 1.6.51 has been released to address four buffer overflow vulnerabilities discovered through fuzzing and security research. The release fixes two high-severity and two moderate-severity CVEs (CVE-2025-64505, CVE-2025-64506, CVE-2025-64720, CVE-2025-65018). The announcement was made via email to the oss-security mailing list, providing security updates for the widely-used PNG image library.
Key quotes
· 4 pulledlibpng 1.6.51 has been released to address four buffer overflow vulnerabilities discovered through fuzzing and security research.
This release fixes two high-severity and two moderate-severity CV
Message-ID: <CAAoVtZw-pkvsSTaXAHjDdUC3NRDwvwVNT8D4BpO5z3d79W-FVg@mail.gmail.com>
Subject: libpng 1.6.51: Four buffer overflow vulnerabilities fixed: CVE-2025-64505, CVE-2025-64506, CVE-2025-64720, CVE-2025-65018
You might also wanna read
Anthropic Releases Free Security Plugin for Claude Code Terminal to Detect Vulnerabilities
Anthropic has released a free security-guidance plugin for its Claude Code terminal tool that autonomously reviews code edits, model outputs
cybersecuritynews.com·4h agowolfCOSE: A Lightweight COSE + CBOR Library for Embedded Systems with PQC and FIPS 140-3 Support
wolfCOSE is a lightweight C library implementing CBOR (RFC 8949) and COSE (RFC 9052/9053) for embedded systems, using wolfSSL as the crypto
Anthropic launches Claude Security beta for codebase vulnerability scanning
Anthropic has released Claude Security, a defensive security tool within Claude Code on the web, from closed preview to beta for Claude Ente
thenewstack.io·1d agoHow LinkedIn's 2012 Breach Exposed the Dangers of Unsalted Password Hashes
This article examines the 2012 LinkedIn breach where attackers cracked millions of passwords using fast, unsalted hashes like MD5 and SHA-1.
hendryadrian.com·1d agoAI-Generated npm Package Leaks Its Own GitHub Token, Exposing Malware Operator
A malicious npm package named mouse5212-super-formatter, identified by OX Security, was caught leaking its own hardcoded GitHub token. This
OpenAI brings Codex computer control and mobile access features to Windows
OpenAI has released version 26.527 of the Codex app for Windows, bringing two major features previously exclusive to Mac users: background c
