Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Rajullas

#33924de 53,633
7.8CVSS total
Vulnerabilidades · 1
PT-2017-17594
7.8
2017-03-22
Pngdefry · Pngdefry · CVE-2017-7231
**Name of the Vulnerable Software and Affected Versions** pngdefry versions prior to 2017-03-22 **Description** The issue is related to a heap-based buffer-overflow vulnerability. This occurs because pngdefry fails to properly process a specially crafted png file, affecting the `process()` function in the `pngdefry.c` source file. **Recommendations** For versions prior to 2017-03-22, as a temporary workaround, consider disabling the `process()` function until a patch is available. Restrict access to the `pngdefry.c` source file to minimize the risk of exploitation. Avoid using pngdefry to process untrusted png files until the issue is resolved.