Certain chunk handlers in libpng before 1.0.29 and 1.2.x before 1.2.21 allow remote attackers to cause a denial of service (crash) via crafted (1) pCAL (png_handle_pCAL), (2) sCAL (png_handle_sCAL), (3) tEXt (png_push_read_tEXt), (4) iTXt (png_handle_iTXt), and (5) ztXT (png_handle_ztXt) chunking in PNG images, which trigger out-of-bounds read operations.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Imageio | — | Upgrade macOS to the latest versionApply OS X security update 2008-003 | Dec 16, 2011 | Oct 8, 2007 |
| Apple Osx X11 | — | Apply OS X security update 2008-002 | Dec 16, 2011 | Oct 8, 2007 |
| Freebsd | — | Upgrade png | Dec 10, 2025 | Oct 11, 2007 |
| Gentoo Linux | — | Upgrade media-libs/libpng.Upgrade app-emulation/vmware-server.Upgrade app-emulation/vmware-workstation.Upgrade app-emulation/emul-linux-x86-baselibs.Upgrade app-emulation/vmware-player. | Oct 30, 2017 | Oct 8, 2007 |
| Oracle_linux | — | Upgrade libpng-develUpgrade libpng | Oct 16, 2024 | Oct 8, 2007 |
| Suse | — | Upgrade libpngUpgrade libpng-32bitUpgrade libpng-devel-64bitUpgrade suse-releaseUpgrade libpng-64bitUpgrade libpng-x86Upgrade libpng-devel-32bitUpgrade libpng-devel | Feb 17, 2015 | Oct 8, 2007 |
| Ubuntu | — | Upgrade libpng12-0 | Nov 8, 2024 | Oct 8, 2007 |
| Vmsa 2008 0014 | — | Apply ESX350-200808401-BG. | Nov 19, 2010 | Oct 8, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub