PT-2012-1187 · Libpng+2 · Libpng+2
Mikulas Patocka
·
Published
2012-08-13
·
Updated
2024-09-06
·
CVE-2012-3425
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
libpng versions 1.0.x through 1.0.57
libpng versions 1.2.x through 1.2.47
libpng versions 1.4.x through 1.4.9
libpng versions 1.5.x through 1.5.9
Description
The issue allows remote attackers to cause a denial of service (out-of-bounds read) via a large
avail in field value in a PNG image. This is due to a buffer overflow in the png push read zTXt function.Recommendations
For libpng versions 1.0.x through 1.0.57, update to version 1.0.58 or later.
For libpng versions 1.2.x through 1.2.47, update to version 1.2.48 or later.
For libpng versions 1.4.x through 1.4.9, update to version 1.4.10 or later.
For libpng versions 1.5.x through 1.5.9, update to version 1.5.10 or later.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Ubuntu
Libpng