In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere is no fixed version for RHEL:8 java-1.8.0-openjdk-demo-slowdebug.
Note: Versions mentioned in the description apply only to the upstream java-1.8.0-openjdk-demo-slowdebug package and not the java-1.8.0-openjdk-demo-slowdebug package as distributed by RHEL.
See How to fix? for RHEL:8 relevant fixed versions and status.
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.