Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the png_push_read_zTXt function in pngread.c, and possibly related to (2) pngtest.c.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade media-gfx/povray. | Oct 30, 2017 | Sep 10, 2008 |
| Suse | — | Upgrade libpng12-0-x86Upgrade libpng16-toolsUpgrade libpng16-compat-devel-x86-64-v3Upgrade libpng12-0-32bitUpgrade libpng12-0Upgrade libpng-devel-32bitUpgrade libpng16-develUpgrade libpng16-16-x86-64-v3Upgrade libpng16-devel-x86-64-v3Upgrade libpng-develUpgrade libpng16-16Upgrade libpng16-compat-devel | Aug 9, 2024 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libpng12-0 | Nov 8, 2024 | Sep 11, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub