As a result of bug 324153, splashutils should be upgraded to use libpng-1.4.3. I doubt there is much of a attack vector, but nevertheless...
I have just updated libpng to 1.4.3 in splashutils-1.5.4.3-r3.
I guess it's time for... Arch's, please test & stabilize: =media-gfx/splashutils-1.5.4.3-r3
x86 stable
amd64 done
Marked ppc stable.
GLSA request filed.
security, ping
This issue was resolved and addressed in GLSA 201412-08 at http://security.gentoo.org/glsa/glsa-201412-08.xml by GLSA coordinator Sean Amoss (ackle).