First published: Wed Jul 10 2019(Updated: )
dnsjava is vulnerable to a denial of service, caused by an error when using the ValidatingResolver for DNSSEC validation. By using specially crafted DNSSEC-signed zones, an attacker could exploit this vulnerability to exhaust all available CPU resources.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libpng Libpng | <1.6.32 | |
Netapp Active Iq Unified Manager Vsphere | ||
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12652 is a vulnerability in libpng before 1.6.32 that allows an attacker to bypass user limits by exploiting a flaw in chunk length checking.
CVE-2017-12652 has a severity rating of 9.8 (Critical).
The vulnerability affects libpng versions before 1.6.32 and Netapp Active Iq Unified Manager.
To fix CVE-2017-12652, update libpng to version 1.6.32 or later and follow any recommended security advisories from Netapp for Active Iq Unified Manager.
You can find more information about CVE-2017-12652 on the following references: http://www.securityfocus.com/bid/109269, https://github.com/glennrp/libpng/blob/df7e9dae0c4aac63d55361e35709c864fa1b8363/ANNOUNCE, and https://security.netapp.com/advisory/ntap-20220506-0003/