Buffer overflow in the BMP reader in OptiPNG 0.6 and 0.6.1 allows user-assisted attackers to execute arbitrary code via a crafted BMP image, related to an "array overflow."
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade optipng | Jul 30, 2024 | Nov 17, 2008 |
| Freebsd | — | Upgrade optipng | Dec 10, 2025 | Jan 19, 2009 |
| Gentoo Linux | — | Upgrade media-gfx/optipng. | Oct 30, 2017 | Nov 17, 2008 |
| Suse | — | Upgrade optipng | Feb 17, 2015 | Nov 17, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub