CVE-2009-0749: Use After Free
Use-after-free vulnerability in the GIFReadNextExtension function in lib/pngxtern/gif/gifread.c in OptiPNG 0.6.2 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a crafted GIF image that causes the realloc function to return a new pointer, which triggers memory corruption when the old pointer is accessed.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0749?
CVE-2009-0749 has a severity rating that can lead to denial of service through application crashes.
How do I fix CVE-2009-0749?
To fix CVE-2009-0749, upgrade to OptiPNG version 0.6.3 or later.
What versions of OptiPNG are affected by CVE-2009-0749?
OptiPNG versions 0.6.2 and earlier are affected by CVE-2009-0749.
What type of vulnerability is CVE-2009-0749?
CVE-2009-0749 is categorized as a use-after-free vulnerability.
Can CVE-2009-0749 impact system security?
Yes, CVE-2009-0749 can impact system security by causing crashes that may lead to service interruptions.