PT-2017-8754 · Pngquant+1 · Pngquant+1

Choi Jaeseung

·

Published

2016-07-28

·

Updated

2024-06-15

·

CVE-2016-5735

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pngquant version 2.7.0
Description The issue is related to an integer overflow in the rwpng read image24 libpng function, which can be triggered by a crafted PNG file. This overflow can lead to a buffer overflow, potentially allowing remote attackers to have an unspecified impact.
Recommendations For pngquant version 2.7.0, update to a newer version that contains a fix for this issue.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1791
CVE-2016-5735
DLA-2257-1
DLA-966-1
OPENSUSE-SU-2024:10972-1

Affected Products

Alt Linux
Pngquant