CVE-2025-28162: Buffer Overflow
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28162?
CVE-2025-28162 is classified as a high-severity buffer overflow vulnerability that can lead to denial of service.
How do I fix CVE-2025-28162?
To fix CVE-2025-28162, upgrade libpng to version 1.6.47 or later.
What causes the denial of service in CVE-2025-28162?
The denial of service in CVE-2025-28162 is caused by high memory usage leading to an unresponsive program due to buffer overflow.
Who is affected by CVE-2025-28162?
CVE-2025-28162 affects users of libpng versions 1.6.43 to 1.6.46.
What forms of attacks are possible with CVE-2025-28162?
An attacker can exploit CVE-2025-28162 locally to trigger a buffer overflow, causing the application to crash.