CVE-2007-5267: Medium severity libpng LIBPNG vulnerability
Off-by-one error in ICC profile chunk handling in the pngsetiCCP function in pngset.c in libpng before 1.2.22 beta1 allows remote attackers to cause a denial of service (crash) via a crafted PNG image, due to an incorrect fix for CVE-2007-5266.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5267?
CVE-2007-5267 has a medium severity rating, as it can lead to a denial of service due to application crashes.
How do I fix CVE-2007-5267?
To fix CVE-2007-5267, upgrade libpng to version 1.2.22 beta1 or later, which addresses this vulnerability.
What types of attacks can exploit CVE-2007-5267?
CVE-2007-5267 can be exploited by remote attackers using crafted PNG images that take advantage of the off-by-one error.
Which versions of libpng are affected by CVE-2007-5267?
CVE-2007-5267 affects libpng versions prior to 1.2.22 beta1.
What is the impact of CVE-2007-5267 on applications using libpng?
The impact of CVE-2007-5267 on applications using libpng is that it may cause them to crash when processing specially crafted PNG files.