PT-2007-6349 · Libpng · Libpng

Ben

·

Published

2007-10-08

·

Updated

2018-10-15

·

CVE-2007-5267

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: libpng versions prior to 1.2.22 beta1
Description: The issue is caused by an off-by-one error in ICC profile chunk handling in the png set iCCP function in pngset.c. This error allows remote attackers to cause a denial of service (crash) via a crafted PNG image. The issue arose due to an incorrect fix for a previous problem.
Recommendations: For versions prior to 1.2.22 beta1, update to version 1.2.22 beta1 or later to resolve the issue. As a temporary workaround, consider restricting the handling of ICC profile chunks in the png set iCCP function to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5267

Affected Products

Libpng