The png_handle_cHRM function in pngrutil.c in libpng 1.5.4, when color-correction support is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed PNG image containing a cHRM chunk associated with a certain zero value.
CVSS Details
- CVSS 3.1 Base Score: 3.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Addressbook | — | Upgrade macOS to the latest versionApply OS X security update 2012-001 | Aug 28, 2015 | Jan 17, 2012 |
| Apple Osx Imageio | — | Upgrade macOS to the latest versionApply OS X security update 2012-002 | Feb 3, 2012 | Jan 17, 2012 |
| Apple Osx Loginwindow | — | Apply OS X security update 2012-002Upgrade macOS to the latest version | Aug 28, 2015 | Jan 17, 2012 |
| Apple Osx Php | — | Apply OS X security update 2012-001Upgrade macOS to the latest version | Feb 3, 2012 | Jan 17, 2012 |
| Suse | — | Upgrade libpng16-16-32bitUpgrade libpng15-15Upgrade libpng16-compat-devel-x86-64-v3Upgrade libpng16-devel-x86-64-v3Upgrade libpng16-toolsUpgrade libpng16-develUpgrade libpng16-16-x86-64-v3Upgrade libpng16-16Upgrade libpng16-compat-devel | Aug 9, 2024 | Jul 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub