Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade mozilla-gtk1Upgrade pt_BR-netscape7Upgrade fr-netscape7Upgrade netscape-communicatorUpgrade ko-netscape-navigator-linuxUpgrade linux-netscape-communicatorUpgrade linux-mozillaUpgrade ja-netscape7Upgrade pngUpgrade linux-pngUpgrade de-netscape7Upgrade mozillaUpgrade netscape7Upgrade ja-netscape-communicator-linuxUpgrade ko-netscape-communicator-linuxUpgrade ja-netscape-navigator-linuxUpgrade netscape-navigatorUpgrade firefoxUpgrade linux-netscape-navigatorUpgrade thunderbirdUpgrade linux-mozilla-devel | Dec 10, 2025 | Aug 4, 2004 |
| Gentoo Linux | — | Upgrade www-client/galeon.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla.Upgrade www-client/epiphany.Upgrade www-client/mozilla-bin.Upgrade media-libs/libpng.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | Nov 23, 2004 |
| Suse | — | Upgrade libpng-64bitUpgrade libpng-32bitUpgrade libpng-x86Upgrade libpng | Feb 17, 2015 | Nov 23, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub