PT-2007-6349 · Libpng · Libpng
Ben
·
Published
2007-10-08
·
Updated
2018-10-15
·
CVE-2007-5267
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
libpng versions prior to 1.2.22 beta1
Description:
The issue is caused by an off-by-one error in ICC profile chunk handling in the png set iCCP function in pngset.c. This error allows remote attackers to cause a denial of service (crash) via a crafted PNG image. The issue arose due to an incorrect fix for a previous problem.
Recommendations:
For versions prior to 1.2.22 beta1, update to version 1.2.22 beta1 or later to resolve the issue. As a temporary workaround, consider restricting the handling of ICC profile chunks in the png set iCCP function to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libpng