The sPLT chunk handling code (png_set_sPLT function in pngset.c) in libpng 1.0.6 through 1.2.12 uses a sizeof operator on the wrong data type, which allows context-dependent attackers to cause a denial of service (crash) via malformed sPLT chunks that trigger an out-of-bounds read.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx X11 | — | Apply OS X security update 2008-002 | Dec 16, 2011 | Nov 17, 2006 |
| Gentoo Linux | — | Upgrade media-libs/libpng. | Oct 30, 2017 | Nov 17, 2006 |
| Oracle_linux | — | Upgrade libpngUpgrade libpng-devel | Oct 16, 2024 | Nov 17, 2006 |
| Suse | — | Upgrade libpng12-0-x86Upgrade libpng16-16Upgrade libpng16-develUpgrade libpng12-0Upgrade libpng12-0-32bitUpgrade libpng-develUpgrade libpng16-devel-x86-64-v3Upgrade libpng16-16-x86-64-v3Upgrade libpng-devel-32bitUpgrade libpng16-compat-develUpgrade libpng16-compat-devel-x86-64-v3Upgrade libpng16-tools | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libpng12-0Upgrade libpng10-0 | Nov 8, 2024 | Nov 17, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub