CVE-2012-3425: Buffer Overflow
The pngpushreadzTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large availin field value in a PNG image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3425?
CVE-2012-3425 has a severity rating that allows remote attackers to cause a denial of service through an out-of-bounds read.
How do I fix CVE-2012-3425?
To fix CVE-2012-3425, update libpng to version 1.0.58, 1.2.48, 1.4.10, or 1.5.10 or later.
Which versions of libpng are affected by CVE-2012-3425?
CVE-2012-3425 affects libpng versions 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10.
What type of vulnerability is CVE-2012-3425?
CVE-2012-3425 is a vulnerability that allows for denial of service through an out-of-bounds read.
Are multiple operating systems affected by CVE-2012-3425?
Yes, CVE-2012-3425 affects multiple operating systems including Ubuntu and openSUSE that use the vulnerable versions of libpng.