CVE-2017-12652: Input Validation
dnsjava is vulnerable to a denial of service, caused by an error when using the ValidatingResolver for DNSSEC validation. By using specially crafted DNSSEC-signed zones, an attacker could exploit this vulnerability to exhaust all available CPU resources.
Other sources
libpng before 1.6.32 does not properly check the length of chunks against the user limit.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-12652?
CVE-2017-12652 is a vulnerability in libpng before 1.6.32 that allows an attacker to bypass user limits by exploiting a flaw in chunk length checking.
How severe is CVE-2017-12652?
CVE-2017-12652 has a severity rating of 9.8 (Critical).
Which software is affected by CVE-2017-12652?
The vulnerability affects libpng versions before 1.6.32 and Netapp Active Iq Unified Manager.
How can I fix CVE-2017-12652?
To fix CVE-2017-12652, update libpng to version 1.6.32 or later and follow any recommended security advisories from Netapp for Active Iq Unified Manager.
Where can I find more information about CVE-2017-12652?
You can find more information about CVE-2017-12652 on the following references: http://www.securityfocus.com/bid/109269, https://github.com/glennrp/libpng/blob/df7e9dae0c4aac63d55361e35709c864fa1b8363/ANNOUNCE, and https://security.netapp.com/advisory/ntap-20220506-0003/