First published: Sun Jul 22 2012(Updated: )
Off-by-one error in the png_formatted_warning function in pngerror.c in libpng 1.5.4 through 1.5.7 might allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified vectors, which trigger a stack-based buffer overflow.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libpng Libpng | =1.5.7 | |
Libpng Libpng | =1.5.1 | |
Libpng Libpng | =1.5.6-beta | |
Libpng Libpng | =1.5.3-beta | |
Libpng Libpng | =1.5.4-beta | |
Libpng Libpng | =1.5.5 | |
Libpng Libpng | =1.5.0-beta | |
Libpng Libpng | =1.5.1-beta | |
Libpng Libpng | =1.5.4 | |
Libpng Libpng | =1.5.6 | |
Libpng Libpng | =1.5.5-beta | |
Libpng Libpng | =1.5.2 | |
Libpng Libpng | =1.5.7-beta | |
Libpng Libpng | =1.5.2-beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.