Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Imageio | — | Upgrade macOS to the latest versionApply OS X security update 2012-004 | Sep 27, 2012 | Feb 16, 2012 |
| Apple Osx Note | — | Apply OS X security update 2012-004Upgrade macOS to the latest version | Aug 28, 2015 | Feb 16, 2012 |
| Centos_linux | — | Upgrade thunderbirdUpgrade seamonkey-chatUpgrade libpngUpgrade libpng10-develUpgrade libpng-develUpgrade seamonkeyUpgrade seamonkey-dom-inspectorUpgrade libpng-staticUpgrade seamonkey-mailUpgrade firefoxUpgrade libpng10Upgrade xulrunnerUpgrade seamonkey-develUpgrade seamonkey-js-debuggerUpgrade xulrunner-devel | Dec 1, 2016 | Feb 16, 2012 |
| Freebsd | — | Upgrade linux-firefoxUpgrade linux-thunderbirdUpgrade linux-seamonkeyUpgrade firefoxUpgrade thunderbirdUpgrade seamonkey | Dec 10, 2025 | Feb 17, 2012 |
| Gentoo Linux | — | Upgrade dev-libs/nss.Upgrade www-client/firefox.Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/thunderbird-bin.Upgrade www-client/icecat.Upgrade mail-client/thunderbird.Upgrade net-libs/xulrunner.Upgrade www-client/seamonkey.Upgrade www-client/firefox-bin.Upgrade net-libs/xulrunner-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade media-libs/libpng.Upgrade mail-client/mozilla-thunderbird. | Oct 30, 2017 | Feb 16, 2012 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Mar 21, 2012 | Feb 16, 2012 |
| Mfsa2012 11 | — | Upgrade to Mozilla Firefox version 10.0.2Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 3.6.27Upgrade to Mozilla Firefox ESR version 10.0.2 | Jun 14, 2012 | Feb 16, 2012 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.7.2 | Feb 17, 2012 | Feb 16, 2012 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 10.0.2Upgrade to Mozilla Thunderbird ESR version 10.0.2Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 3.1.19 | Feb 22, 2012 | Feb 16, 2012 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.1.0.0.24.2 on Solaris 11.1 | May 29, 2017 | Feb 16, 2012 |
| Oracle_linux | — | Upgrade thunderbirdUpgrade libpng-staticUpgrade libpng-develUpgrade libpng | Oct 16, 2024 | Feb 16, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 16, 2012 |
| Suse | — | Upgrade MozillaThunderbird-translations-otherUpgrade mozilla-xulrunner192-gnomeUpgrade libpng12-0Upgrade libpng12-compat-develUpgrade mozilla-xulrunner192-develUpgrade mozilla-xulrunner192-translations-32bitUpgrade mozilla-xulrunner192-x86Upgrade mozilla-xulrunner192Upgrade MozillaFirefox-translationsUpgrade libpng12-develUpgrade mozilla-xulrunner192-gnome-32bitUpgrade libpng15-15Upgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-commonUpgrade mozilla-xulrunner192-translationsUpgrade MozillaThunderbird-develUpgrade mozilla-xulrunner192-32bitUpgrade libpng12-0-x86Upgrade MozillaFirefoxUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-commonUpgrade libpng-devel-32bitUpgrade libpng12-0-32bitUpgrade libpng-develUpgrade MozillaFirefox-translations-otherUpgrade chromium | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade thunderbirdUpgrade firefoxUpgrade libpng12-0Upgrade xulrunner-1.9.2 | Nov 8, 2024 | Feb 16, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub