PT-2022-6893 · Libpng+1 · Libpng+1

5Hadowblad3

·

Published

2022-08-24

·

Updated

2022-11-08

·

CVE-2021-4214

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libpng (affected versions not specified)
Description The issue is caused by a heap overflow flaw in the pngimage.c component of the libpng library. This flaw can be exploited by an attacker with local network access, allowing them to pass a specially crafted PNG file to the pngimage utility. As a result, the application may crash, leading to a denial of service. The attacker can use this flaw to cause the application to crash by passing a specially crafted PNG file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-05417
CVE-2021-4214
ECHO-98CD-F196-FFAF

Affected Products

Debian
Libpng