libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx X11 | — | Apply OS X security update 2010-002Upgrade macOS to the latest version | Dec 16, 2011 | Jun 12, 2009 |
| Centos_linux | — | Upgrade libpngUpgrade libpng-develUpgrade libpng10Upgrade libpng10-devel | Dec 1, 2016 | Jun 12, 2009 |
| Gentoo Linux | — | Upgrade net-mail/mlmmj.Upgrade app-arch/gzip.Upgrade dev-libs/liblzw.Upgrade app-text/dvipng.Upgrade media-libs/libpng.Upgrade dev-util/sourcenav.Upgrade media-gfx/splashutils.Upgrade dev-perl/perl-tk.Upgrade sys-auth/pam_krb5.Upgrade sys-apps/acl.Upgrade dev-lang/tk.Upgrade x11-libs/gtk+.Upgrade dev-util/insight.Upgrade app-arch/ncompress.Upgrade app-misc/beanstalkd.Upgrade net-ftp/lftp.Upgrade app-antivirus/bitdefender-console.Upgrade kde-base/kget.Upgrade kde-base/kdm.Upgrade sys-block/partimage.Upgrade www-client/uzbl.Upgrade app-text/gv.Upgrade x11-apps/xinit.Upgrade net-misc/iputils.Upgrade media-tv/dvbstreamer.Upgrade x11-misc/slim.Upgrade sys-apps/pmount.Upgrade sys-devel/m4. | Oct 30, 2017 | Jun 12, 2009 |
| Oracle_linux | — | Upgrade libpngUpgrade libpng-devel | Oct 16, 2024 | Jun 12, 2009 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 4, 2009 |
| Suse | — | Upgrade libpng12-0-32bitUpgrade libpng12-0Upgrade libpng-develUpgrade libpng12-0-x86Upgrade libpng-devel-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libpng12-0 | Nov 8, 2024 | Jun 12, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub