Back

LOW

libpng DoS

Published Nov 17, 2006

Description

The sPLT chunk handling code (png_set_sPLT function in pngset.c) in libpng 1.0.6 through 1.2.12 uses a sizeof operator on the wrong data type, which allows context-dependent attackers to cause a denial of service (crash) via malformed sPLT chunks that trigger an out-of-bounds read.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (47)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 17, 2006
Updated Aug 7, 2024
Reserved Nov 8, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Nov 14, 2006