PT-2006-1547 · Libpng+1 · Libpng+1
Josh Bressers
·
Published
2006-01-31
·
Updated
2017-10-11
·
CVE-2006-0481
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
libpng version 1.2.7
Description
A heap-based buffer overflow issue exists in the alpha strip capability of libpng, allowing context-dependent attackers to cause a denial of service (crash) when the
png do strip filler function is used to strip alpha channels out of an image.Recommendations
For libpng version 1.2.7, consider updating to a newer version to mitigate the risk of a denial of service (crash) when using the
png do strip filler function to strip alpha channels out of an image. As a temporary workaround, consider disabling the use of the png do strip filler function until a patch is available.Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Libpng