Security Advisory: CVE-2022-3857
ubi-micro-dev Opinion:
This CVE has been rejected upstream, because this flaw does not exist and was erroneously tested. This issue has been marked as a false-positive -
https://sourceforge.net/p/libpng/bugs/300/. Consider a global exception policy for this CVE.
Description:
[REJECTED CVE] A issue has been identified with libpng in png_setup_paeth_row() function. A crafted PNG image from a n attacker can lead to a segmentation fault and Denial of service.
Locations:
- java-17-openjdk-headless-1:17.0.16.0.8-2.el8
References: