PT-2016-1709 · Open Source+2 · Optipng+2
Henri Salo
·
Publicado
2016-04-07
·
Atualizado
2021-07-31
·
CVE-2016-3981
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OptiPNG versions prior to 0.7.6
Description
The issue is related to a heap-based buffer overflow in the
bmp read rows function, which can be triggered by a crafted image file. This could allow remote attackers to cause a denial of service, such as out-of-bounds read or write access and crash, or possibly execute arbitrary code.Recommendations
For versions prior to 0.7.6, update to version 0.7.6 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the
bmp read rows function until a patch is available. Restrict access to crafted image files to minimize the risk of exploitation.Exploit
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Optipng
Ubuntu