Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-6129

Опубликовано: 11 янв. 2019
Источник: redhat
CVSS3: 3.3

Описание

png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.

A memory leak was found in the pngcp.c utility of libpng. The pngcp utility fails to free the png_info structure allocated by png_create_info_struct before exiting.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libpngNot affected
Red Hat Enterprise Linux 6libpngNot affected
Red Hat Enterprise Linux 7libpngNot affected
Red Hat Enterprise Linux 7libpng12Not affected
Red Hat Enterprise Linux 8libpngNot affected
Red Hat Enterprise Linux 8libpng12Not affected
Red Hat Enterprise Linux 8mingw-libpngNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1667127libpng: memory leak of png_info struct in pngcp.c

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 7 лет назад

png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.

CVSS3: 6.5
nvd
около 7 лет назад

png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.

CVSS3: 6.5
debian
около 7 лет назад

png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as ...

CVSS3: 6.5
github
больше 3 лет назад

** DISPUTED ** png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer."

CVSS3: 6.5
fstec
около 7 лет назад

Уязвимость функции png_create_info_struct библиотеки для работы с растровой графикой в формате PNG libpng, позволяющая нарушителю вызвать отказ в обслуживании

3.3 Low

CVSS3