First published: Fri Jan 21 2022(Updated: )
A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libpng Libpng | =1.6.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
NetApp ONTAP Select Deploy administration utility | ||
debian/libpng1.6 | <=1.6.37-3<=1.6.39-2<=1.6.43-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-4214 is a heap overflow vulnerability found in libpng's pngimage.c program.
The severity of CVE-2021-4214 is medium.
CVE-2021-4214 affects libpng version 1.6.0 and Debian Linux versions 10.0 and 11.0, as well as the NetApp ONTAP Select Deploy administration utility.
An attacker with local network access can exploit CVE-2021-4214 by passing a specially crafted PNG file to the pngimage utility, causing an application to crash and leading to a denial of service.
To fix the CVE-2021-4214 vulnerability, update libpng to versions 1.6.36-6, 1.6.37-3, 1.6.39-2, or 1.6.40-2, or follow the recommended updates for the affected software.