Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade libpng-staticUpgrade libpngUpgrade libpng-devel | Dec 1, 2016 | Mar 22, 2012 |
| Gentoo Linux | — | Upgrade media-libs/libpng. | Oct 30, 2017 | Mar 22, 2012 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Sep 17, 2012 | Mar 22, 2012 |
| Huawei Euleros 2_0_sp10 | — | Upgrade syslinuxUpgrade syslinux-nonlinux | Nov 11, 2024 | Mar 22, 2012 |
| Huawei Euleros 2_0_sp11 | — | Upgrade syslinux-nonlinuxUpgrade syslinux | Dec 12, 2024 | Mar 22, 2012 |
| Huawei Euleros 2_0_sp12 | — | Upgrade syslinuxUpgrade syslinux-nonlinux | Dec 12, 2024 | Mar 22, 2012 |
| Huawei Euleros 2_0_sp9 | — | Upgrade syslinux-nonlinuxUpgrade syslinux | Nov 11, 2024 | Mar 22, 2012 |
| Oracle_linux | — | Upgrade libpng-develUpgrade libpngUpgrade libpng-static | Oct 16, 2024 | Mar 22, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 8, 2012 |
| Suse | — | Upgrade chromiumUpgrade libpng12-develUpgrade libpng12-0Upgrade libpng12-0-32bitUpgrade libpng12-compat-devel | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libpng12-0 | Nov 8, 2024 | Mar 22, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub