First published: Thu Aug 05 2004(Updated: )
The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libpng | <=1.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0598 has been assigned a medium severity rating due to its potential to cause denial of service attacks.
To fix CVE-2004-0598, update libpng to version 1.2.6 or later, which addresses this vulnerability.
CVE-2004-0598 is a denial of service vulnerability that can lead to application crashes.
CVE-2004-0598 affects libpng versions 1.2.5 and earlier.
Yes, CVE-2004-0598 can be exploited remotely by sending a specially crafted PNG image.