Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade ko-netscape-navigator-linuxUpgrade ja-netscape-navigator-linuxUpgrade ja-netscape-communicator-linuxUpgrade ko-netscape-communicator-linuxUpgrade firefoxUpgrade netscape7Upgrade linux-netscape-navigatorUpgrade thunderbirdUpgrade linux-mozillaUpgrade linux-mozilla-develUpgrade fr-netscape7Upgrade netscape-navigatorUpgrade linux-pngUpgrade mozillaUpgrade linux-netscape-communicatorUpgrade de-netscape7Upgrade netscape-communicatorUpgrade pngUpgrade ja-netscape7Upgrade mozilla-gtk1Upgrade pt_BR-netscape7 | Dec 10, 2025 | Aug 4, 2004 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox.Upgrade media-libs/libpng.Upgrade www-client/galeon.Upgrade www-client/mozilla-bin.Upgrade www-client/epiphany.Upgrade www-client/mozilla.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/mozilla-thunderbird. | Oct 30, 2017 | Nov 23, 2004 |
| Suse | — | Upgrade libpng-64bitUpgrade libpngUpgrade libpng-x86Upgrade libpng-32bit | Feb 17, 2015 | Nov 23, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub