Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Jun 25, 2026 | Jan 5, 2024 |
| Apple Osx Imageio | — | Upgrade macOS to the latest versionApply OS X security update 2010-007 | Dec 16, 2011 | Jun 30, 2010 |
| Apple Osx X11 | — | Upgrade macOS to the latest versionApply OS X security update 2010-007 | Dec 16, 2011 | Jun 30, 2010 |
| Apple Safari | — | Uninstall Apple Safari on WindowsUpgrade to Apple Safari version 5.0.4 | Jan 5, 2012 | Jun 30, 2010 |
| Centos_linux | — | Upgrade libpng10-develUpgrade libpng-develUpgrade libpngUpgrade libpng10 | Dec 1, 2016 | Jun 30, 2010 |
| Debian | — | Upgrade tuxonice-userui | Jul 30, 2024 | Jun 30, 2010 |
| Gentoo Linux | — | Upgrade media-libs/libpng. | Oct 30, 2017 | Jun 30, 2010 |
| Oracle_linux | — | Upgrade libpngUpgrade libpng-devel | Oct 16, 2024 | Jun 30, 2010 |
| Suse | — | Upgrade libpng12-0-32bitUpgrade libpng12-0Upgrade libpng-develUpgrade libpng-devel-32bitUpgrade libpng12-0-x86 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libpng12-0 | Nov 8, 2024 | Jun 30, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub