libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx X11 | — | Apply OS X security update 2010-002Upgrade macOS to the latest version | Dec 16, 2011 | Jun 12, 2009 |
| Centos_linux | — | Upgrade libpng10Upgrade libpngUpgrade libpng-develUpgrade libpng10-devel | Dec 1, 2016 | Jun 12, 2009 |
| Gentoo Linux | — | Upgrade media-libs/libpng.Upgrade net-ftp/lftp.Upgrade dev-util/insight.Upgrade x11-libs/gtk+.Upgrade media-gfx/splashutils.Upgrade app-arch/ncompress.Upgrade dev-lang/tk.Upgrade app-misc/beanstalkd.Upgrade app-arch/gzip.Upgrade dev-util/sourcenav.Upgrade app-text/dvipng.Upgrade net-mail/mlmmj.Upgrade sys-apps/acl.Upgrade dev-perl/perl-tk.Upgrade sys-auth/pam_krb5.Upgrade dev-libs/liblzw.Upgrade app-text/gv.Upgrade net-misc/iputils.Upgrade kde-base/kdm.Upgrade media-tv/dvbstreamer.Upgrade x11-apps/xinit.Upgrade sys-apps/pmount.Upgrade kde-base/kget.Upgrade www-client/uzbl.Upgrade x11-misc/slim.Upgrade sys-devel/m4.Upgrade app-antivirus/bitdefender-console.Upgrade sys-block/partimage. | Oct 30, 2017 | Jun 12, 2009 |
| Oracle_linux | — | Upgrade libpngUpgrade libpng-devel | Oct 16, 2024 | Jun 12, 2009 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 4, 2009 |
| Suse | — | Upgrade libpng-develUpgrade libpng12-0-32bitUpgrade libpng12-0Upgrade libpng12-0-x86Upgrade libpng-devel-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libpng12-0 | Nov 8, 2024 | Jun 12, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub