libpng 1.2.5 and earlier does not properly calculate certain buffer offsets, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.
https://exchange.xforce.ibmcloud.com/vulnerabilities/16914
https://bugzilla.fedora.us/show_bug.cgi?id=1943
http://www.debian.org/security/2004/dsa-536