The png_handle_tRNS function in pngrutil.c in libpng before 1.0.25 and 1.2.x before 1.2.17 allows remote attackers to cause a denial of service (application crash) via a grayscale PNG image with a bad tRNS chunk CRC value.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx X11 | — | Apply OS X security update 2008-002 | Dec 16, 2011 | May 16, 2007 |
| Debian | — | Upgrade libgd2 | Jul 30, 2024 | May 16, 2007 |
| Freebsd | — | Upgrade png | Dec 10, 2025 | May 16, 2007 |
| Gentoo Linux | — | Upgrade app-emulation/emul-linux-x86-baselibs.Upgrade media-libs/libpng. | Oct 30, 2017 | May 16, 2007 |
| Oracle_linux | — | Upgrade libpngUpgrade libpng-devel | Oct 16, 2024 | May 16, 2007 |
| Suse | — | Upgrade libpng-x86Upgrade libpng-64bitUpgrade libpng-develUpgrade libpng-32bitUpgrade libpng-devel-32bitUpgrade libpngUpgrade libpng-devel-64bitUpgrade suse-release | Feb 17, 2015 | May 16, 2007 |
| Ubuntu | — | Upgrade libpng12-0 | Nov 8, 2024 | May 16, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub