xvpng.c in xv 3.10a has memory corruption (out-of-bounds write) when decoding PNG comment fields, leading to crashes or potentially code execution, because it uses an incorrect length value.
| Software | From | Fixed in |
|---|---|---|
| xv_project / xv | 3.10a | 3.10a.x |
| opensuse / leap | 42.3 | 42.3.x |