The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function call using a NULL pointer argument instead of an empty-string argument, which allows remote attackers to cause a denial of service (application crash) via a crafted PNG image.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2011-006 | Aug 28, 2015 | Jul 17, 2011 |
| Apple Osx Php | — | Upgrade macOS to the latest versionApply OS X security update 2011-006 | Dec 16, 2011 | Jul 17, 2011 |
| Apple Osx X11 | — | Apply OS X security update 2011-006Upgrade macOS to the latest version | Dec 16, 2011 | Jul 17, 2011 |
| Gentoo Linux | — | Upgrade media-libs/libpng. | Oct 30, 2017 | Jul 17, 2011 |
| Huawei Euleros 2_0_sp10 | — | Upgrade syslinuxUpgrade syslinux-nonlinux | Nov 11, 2024 | Jul 17, 2011 |
| Huawei Euleros 2_0_sp11 | — | Upgrade syslinuxUpgrade syslinux-nonlinux | Dec 12, 2024 | Jul 17, 2011 |
| Huawei Euleros 2_0_sp12 | — | Upgrade syslinux-nonlinuxUpgrade syslinux | Dec 12, 2024 | Jul 17, 2011 |
| Huawei Euleros 2_0_sp9 | — | Upgrade syslinuxUpgrade syslinux-nonlinux | Nov 11, 2024 | Jul 17, 2011 |
| Suse | — | Upgrade libpng16-16-32bitUpgrade libpng16-devel-x86-64-v3Upgrade libpng16-toolsUpgrade libpng15-15Upgrade libpng16-develUpgrade libpng12-0-x86Upgrade libpng12-0-32bitUpgrade libpng16-compat-devel-x86-64-v3Upgrade libpng12-0Upgrade libpng16-16Upgrade libpng16-compat-develUpgrade libpng16-16-x86-64-v3Upgrade libpng-devel-32bitUpgrade libpng-devel | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade chromium-browserUpgrade firefox | Nov 19, 2024 | Jul 17, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub