The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null dereference.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade de-netscape7Upgrade linux-pngUpgrade mozillaUpgrade netscape-navigatorUpgrade mozilla-gtk1Upgrade linux-mozillaUpgrade netscape-communicatorUpgrade linux-mozilla-develUpgrade ja-netscape7Upgrade thunderbirdUpgrade fr-netscape7Upgrade pngUpgrade linux-netscape-communicatorUpgrade ja-netscape-communicator-linuxUpgrade netscape7Upgrade pt_BR-netscape7Upgrade ja-netscape-navigator-linuxUpgrade ko-netscape-navigator-linuxUpgrade linux-netscape-navigatorUpgrade ko-netscape-communicator-linuxUpgrade firefox | Dec 10, 2025 | Aug 4, 2004 |
| Gentoo Linux | — | Upgrade www-client/epiphany.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/mozilla-bin.Upgrade media-libs/libpng.Upgrade www-client/mozilla.Upgrade www-client/mozilla-firefox.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/galeon. | Oct 30, 2017 | Nov 23, 2004 |
| Suse | — | Upgrade libpng-64bitUpgrade libpng-x86Upgrade libpng-32bitUpgrade libpng | Feb 17, 2015 | Nov 23, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub