Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the png_rgb_to_gray function but not the png_set_expand function, allows remote attackers to overwrite memory with an arbitrary amount of data, and possibly have unspecified other impact, via a crafted PNG image.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2011-006 | Aug 28, 2015 | Jul 17, 2011 |
| Apple Osx Php | — | Upgrade macOS to the latest versionApply OS X security update 2011-006 | Dec 16, 2011 | Jul 17, 2011 |
| Apple Osx X11 | — | Apply OS X security update 2011-006Upgrade macOS to the latest version | Dec 16, 2011 | Jul 17, 2011 |
| Centos_linux | — | Upgrade libpngUpgrade libpng-devel | Dec 1, 2016 | Jul 17, 2011 |
| Gentoo Linux | — | Upgrade media-libs/libpng. | Oct 30, 2017 | Jul 17, 2011 |
| Huawei Euleros 2_0_sp10 | — | Upgrade syslinux-nonlinuxUpgrade syslinux | Nov 11, 2024 | Jul 17, 2011 |
| Huawei Euleros 2_0_sp11 | — | Upgrade syslinux-nonlinuxUpgrade syslinux | Dec 12, 2024 | Jul 17, 2011 |
| Huawei Euleros 2_0_sp12 | — | Upgrade syslinuxUpgrade syslinux-nonlinux | Dec 12, 2024 | Jul 17, 2011 |
| Huawei Euleros 2_0_sp9 | — | Upgrade syslinux-nonlinuxUpgrade syslinux | Nov 11, 2024 | Jul 17, 2011 |
| Oracle_linux | — | Upgrade libpngUpgrade libpng-develUpgrade libpng-static | Oct 16, 2024 | Jul 17, 2011 |
| Suse | — | Upgrade libpng16-compat-develUpgrade libpng16-toolsUpgrade libpng-devel-32bitUpgrade libpng16-16-x86-64-v3Upgrade libpng16-16Upgrade libpng12-0-x86Upgrade libpng16-16-32bitUpgrade libpng16-devel-x86-64-v3Upgrade libpng12-0Upgrade libpng-develUpgrade libpng12-0-32bitUpgrade libpng15-15Upgrade libpng16-develUpgrade libpng16-compat-devel-x86-64-v3 | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libpng12-0 | Nov 8, 2024 | Jul 17, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub