Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16 might allow context-dependent attackers to execute arbitrary code via a very wide interlaced PNG image. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9495