PT-2016-1709 · Open Source+2 · Optipng+2

Henri Salo

·

Publicado

2016-04-07

·

Atualizado

2021-07-31

·

CVE-2016-3981

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OptiPNG versions prior to 0.7.6
Description The issue is related to a heap-based buffer overflow in the bmp read rows function, which can be triggered by a crafted image file. This could allow remote attackers to cause a denial of service, such as out-of-bounds read or write access and crash, or possibly execute arbitrary code.
Recommendations For versions prior to 0.7.6, update to version 0.7.6 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the bmp read rows function until a patch is available. Restrict access to crafted image files to minimize the risk of exploitation.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1375
BDU:2016-01035
CVE-2016-3981
DSA-3546-1
OESA-2021-1288
USN-2951-1

Produtos afetados

Alt Linux
Optipng
Ubuntu