libpng

Page content
  • Author: Miklos Vajna
  • Vulnerable: 1.2.29-1
  • Unaffected: 1.2.32-1solaria1

A vulnerability has been reported in libpng, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an off-by-one error within the “png_push_read_zTXt()” function in pngread.c when processing malicious PNG images with specially crafted zTXt chunks, which can be exploited to crash an application using the library.

CVEs: