CVE-2006-7244: Medium severity libpng libpng vulnerability
Memory leak in pngwutil.c in libpng 1.2.13beta1, and other versions before 1.2.15beta3, allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a JPEG image containing an iCCP chunk with a negative embedded profile length.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-7244?
CVE-2006-7244 has a severity level that can lead to denial of service through a memory leak or segmentation fault.
How do I fix CVE-2006-7244?
To fix CVE-2006-7244, upgrade to libpng version 1.2.15beta3 or later.
Which versions of libpng are affected by CVE-2006-7244?
CVE-2006-7244 affects libpng versions 1.2.13beta1 and earlier, along with multiple earlier versions.
What types of attacks can exploit CVE-2006-7244?
CVE-2006-7244 can be exploited by attackers through specially crafted JPEG images containing a malicious iCCP chunk.
What are the consequences of CVE-2006-7244?
The consequences of CVE-2006-7244 include possible denial of service due to memory leaks, leading to application crashes.