In libpng until version 1.6.35, a wrong calculation of rowfactor in the pngcheckchunklength function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service. (CVE-2018-13785)
This update fixes it, also providing the current maintenance releases in the 1.2 and 1.6 stable branches.