Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade netscape7Upgrade firefoxUpgrade thunderbirdUpgrade ko-netscape-communicator-linuxUpgrade ja-netscape-communicator-linuxUpgrade netscape-navigatorUpgrade ja-netscape-navigator-linuxUpgrade linux-mozilla-develUpgrade linux-netscape-navigatorUpgrade mozillaUpgrade linux-netscape-communicatorUpgrade ja-netscape7Upgrade fr-netscape7Upgrade pngUpgrade mozilla-gtk1Upgrade netscape-communicatorUpgrade de-netscape7Upgrade linux-pngUpgrade linux-mozillaUpgrade ko-netscape-navigator-linuxUpgrade pt_BR-netscape7 | Dec 10, 2025 | Aug 4, 2004 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox-bin.Upgrade media-libs/libpng.Upgrade www-client/mozilla.Upgrade www-client/epiphany.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-bin.Upgrade www-client/galeon.Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/mozilla-thunderbird-bin. | Oct 30, 2017 | Nov 23, 2004 |
| Suse | — | Upgrade libpng-32bitUpgrade libpng-x86Upgrade libpngUpgrade libpng-64bit | Feb 17, 2015 | Nov 23, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub