Back

HIGH

libpng: "png_handle_tEXt()" memory leak vulnerability - DoS (memory exhaustion) via a crafted PNG file.

Published Feb 20, 2009

Description

Memory leak in the png_handle_tEXt function in pngrutil.c in libpng before 1.2.33 rc02 and 1.4.0 beta36 allows context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted PNG file.

Affected products

Remediation

Red Hat statement

We do not consider a crash of a client application linked to libpng to be a security issue. None of the applications that use libpng are at any risk of causing a denial of service in a meaningful way.

Metrics

Weaknesses (2)

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 20, 2009
Updated Aug 7, 2024
Reserved Feb 20, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Oct 27, 2008