Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade pt_BR-netscape7Upgrade linux-pngUpgrade de-netscape7Upgrade netscape-communicatorUpgrade linux-mozillaUpgrade pngUpgrade ko-netscape-navigator-linuxUpgrade fr-netscape7Upgrade mozilla-gtk1Upgrade linux-netscape-communicatorUpgrade ja-netscape7Upgrade netscape7Upgrade netscape-navigatorUpgrade firefoxUpgrade ja-netscape-navigator-linuxUpgrade mozillaUpgrade ko-netscape-communicator-linuxUpgrade linux-mozilla-develUpgrade linux-netscape-navigatorUpgrade ja-netscape-communicator-linuxUpgrade thunderbird | Dec 10, 2025 | Aug 4, 2004 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox.Upgrade media-libs/libpng.Upgrade www-client/epiphany.Upgrade www-client/mozilla-bin.Upgrade www-client/mozilla.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/galeon. | Oct 30, 2017 | Nov 23, 2004 |
| Suse | — | Upgrade libpng-x86Upgrade libpngUpgrade libpng-32bitUpgrade libpng-64bit | Feb 17, 2015 | Nov 23, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub