1. buffer overwrite in png_rgb_to_gray (CVE-2011-2690) 2. crash in png_default_error due to use of NULL Pointer (CVE-2011-2691) 3. memory corruption when handling empty sCAL chunks (CVE-2011-2692)
1. buffer overwrite in png_rgb_to_gray (CVE-2011-2690) 2. crash in png_default_error due to use of NULL Pointer (CVE-2011-2691) 3. memory corruption when handling empty sCAL chunks (CVE-2011-2692)