First published: Mon Mar 05 2018(Updated: )
xvpng.c in xv 3.10a has memory corruption (out-of-bounds write) when decoding PNG comment fields, leading to crashes or potentially code execution, because it uses an incorrect length value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xv Project Xv | =3.10a | |
openSUSE Leap | =42.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.