Buffer overflow in the png_decompress_chunk function in pngrutil.c in libpng before 1.2.12 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors related to "chunk error processing," possibly involving the "chunk_name".
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx X11 | — | Apply OS X security update 2008-002 | Dec 16, 2011 | Jun 30, 2006 |
| Gentoo Linux | — | Upgrade app-emulation/emul-linux-x86-baselibs.Upgrade media-gfx/povray.Upgrade media-libs/libpng. | Oct 30, 2017 | Jun 30, 2006 |
| Suse | — | Upgrade libpngUpgrade libpng-32bitUpgrade libpng-x86Upgrade libpng-64bitUpgrade libpng-develUpgrade libpng-devel-32bitUpgrade libpng-devel-64bit | Feb 17, 2015 | Jun 30, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub