The png_check_keyword function in pngwutil.c in libpng before 1.0.42, and 1.2.x before 1.2.34, might allow context-dependent attackers to set the value of an arbitrary memory location to zero via vectors involving creation of crafted PNG files with keywords, related to an implicit cast of the '\0' character constant to a NULL pointer. NOTE: some sources incorrectly report this as a double free vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade x11-libs/gtk+.Upgrade dev-libs/liblzw.Upgrade net-misc/iputils.Upgrade www-client/uzbl.Upgrade net-mail/mlmmj.Upgrade dev-lang/tk.Upgrade app-misc/beanstalkd.Upgrade net-ftp/lftp.Upgrade app-arch/ncompress.Upgrade media-libs/libpng.Upgrade dev-perl/perl-tk.Upgrade dev-util/insight.Upgrade sys-apps/acl.Upgrade dev-util/sourcenav.Upgrade sys-auth/pam_krb5.Upgrade kde-base/kdm.Upgrade x11-misc/slim.Upgrade kde-base/kget.Upgrade media-gfx/splashutils.Upgrade app-text/gv.Upgrade x11-apps/xinit.Upgrade sys-block/partimage.Upgrade sys-devel/m4.Upgrade sys-apps/pmount.Upgrade app-text/dvipng.Upgrade app-antivirus/bitdefender-console.Upgrade app-arch/gzip.Upgrade media-tv/dvbstreamer. | Oct 30, 2017 | Jan 15, 2009 |
| Suse | — | Upgrade libpng12-0-x86Upgrade libpng12-0-32bitUpgrade libpng12-0Upgrade libpng-develUpgrade libpng-devel-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libpng12-0 | Nov 8, 2024 | Jan 15, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub