CVE-2007-5266: Medium severity libpng LIBPNG vulnerability
Off-by-one error in ICC profile chunk handling in the pngsetiCCP function in pngset.c in libpng before 1.0.29 beta1 and 1.2.x before 1.2.21 beta1 allows remote attackers to cause a denial of service (crash) via a crafted PNG image that prevents a name field from being NULL terminated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5266?
CVE-2007-5266 has a severity level that is categorized as a denial of service vulnerability.
How do I fix CVE-2007-5266?
To fix CVE-2007-5266, upgrade libpng to version 1.0.29 beta1 or later, or 1.2.21 beta1 or later.
Which versions of libpng are affected by CVE-2007-5266?
CVE-2007-5266 affects libpng versions earlier than 1.0.29 beta1 and versions between 1.2.0 and 1.2.20 inclusive.
What kind of attack does CVE-2007-5266 enable?
CVE-2007-5266 allows remote attackers to cause a denial of service through crafted PNG images.
Is CVE-2007-5266 a critical vulnerability?
CVE-2007-5266 is not categorized as critical, but it can lead to application crashes.