PT-2019-14984 · Lodepng+2 · Lodepng+2
Nico Waisman
·
Published
2015-04-01
·
Updated
2021-07-21
·
CVE-2019-17178
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
LodePNG versions through 2019-09-28
Description
The issue is related to a memory leak in the HuffmanTree makeFromFrequencies function in lodepng.c. This leak occurs because a supplied realloc pointer is also used for a realloc return value. The estimated number of potentially affected devices worldwide is not specified. There is no information provided about real-world incidents where this issue was exploited.
Recommendations
For LodePNG versions through 2019-09-28, update to a version released after 2019-09-28 to resolve the memory leak issue in the HuffmanTree makeFromFrequencies function.
Fix
Memory Leak
Unchecked Return Value
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Lodepng
Suse