CVE-2009-2042

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

Date published : 2009-06-12

http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html

http://www.securityfocus.com/bid/35233