Patching this properly will require not just replacing a centralized copy of libpng, but scanning all binaries for statically-linked copies. There might be some tools left over from the last time libpng got into trouble; this would be a very good time to update and link to them. Some categories of software that are at particularly high risk right now:
* Web browsers. Sandboxing likely helps, but there's a possibility that there are some usages (eg favicons) that decode outside the sandbox.
* MMS on Android (possibly remote root on phones with no user interaction)
* Any server that accepts PNG uploads and processes them (eg, user avatar thumbnail generation)
* Anything which shows people user-provided avatar images (eg, IM clients)
* Video games which download levels that can contain images
* File browsers which show image previews
* Music players which display album covers
Expect malicious images to start appearing everywhere, and soon. If you're responsible for the computer security anywhere, this is a drop-everything priority.