Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-28162

Опубликовано: 27 янв. 2026
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive

A flaw was found in libpng. A local attacker can exploit a buffer overflow vulnerability in the pngimage utility when processed with AddressSanitizer (ASan). This flaw causes memory leaks, leading to high memory usage and ultimately rendering the program unresponsive, resulting in a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of OpenJDK 11 ELSjava-11-openjdkNot affected
Red Hat build of OpenJDK 11 ELSjava-11-openjdk-portableNot affected
Red Hat build of OpenJDK 17java-17-openjdk-portableNot affected
Red Hat build of OpenJDK 1.8java-1.8.0-openjdk-portableNot affected
Red Hat build of OpenJDK 21java-21-openjdk-portableNot affected
Red Hat build of OpenJDK 25java-25-openjdk-portableNot affected
Red Hat Enterprise Linux 10firefoxNot affected
Red Hat Enterprise Linux 10java-21-openjdkNot affected
Red Hat Enterprise Linux 10java-25-openjdkNot affected
Red Hat Enterprise Linux 10libpngNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2433407libpng: libpng: Denial of Service via buffer overflow in pngimage utility

EPSS

Процентиль: 4%
0.00139
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
6 месяцев назад

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive

CVSS3: 5.5
nvd
6 месяцев назад

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive

CVSS3: 5.5
debian
6 месяцев назад

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local a ...

CVSS3: 5.5
github
6 месяцев назад

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive

CVSS3: 5.5
fstec
6 месяцев назад

Уязвимость библиотеки libpng, связанная с копированием буфера без проверки размера входных данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 4%
0.00139
Низкий

6.2 Medium

CVSS3