First published: Wed May 16 2007(Updated: )
The png_handle_tRNS function in pngrutil.c in libpng before 1.0.25 and 1.2.x before 1.2.17 allows remote attackers to cause a denial of service (application crash) via a grayscale PNG image with a bad tRNS chunk CRC value.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux kernel | ||
libpng | <=1.0.15 | |
libpng | <=1.2.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2445 has a severity rated as moderate due to the potential for denial of service.
To fix CVE-2007-2445, upgrade libpng to version 1.0.25 or 1.2.17 or later.
Versions of libpng prior to 1.0.25 and 1.2.17 are vulnerable to CVE-2007-2445.
CVE-2007-2445 allows remote attackers to cause a denial of service due to specific PNG image manipulations.
CVE-2007-2445 affects libpng versions before 1.0.25 and 1.2.17, impacting any application that relies on these versions for handling PNG images.