Описание
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive
A flaw was found in libpng. A local attacker can exploit a buffer overflow vulnerability in the pngimage utility when processed with AddressSanitizer (ASan). This flaw causes memory leaks, leading to high memory usage and ultimately rendering the program unresponsive, resulting in a denial of service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of OpenJDK 11 ELS | java-11-openjdk | Not affected | ||
| Red Hat build of OpenJDK 11 ELS | java-11-openjdk-portable | Not affected | ||
| Red Hat build of OpenJDK 17 | java-17-openjdk-portable | Not affected | ||
| Red Hat build of OpenJDK 1.8 | java-1.8.0-openjdk-portable | Not affected | ||
| Red Hat build of OpenJDK 21 | java-21-openjdk-portable | Not affected | ||
| Red Hat build of OpenJDK 25 | java-25-openjdk-portable | Not affected | ||
| Red Hat Enterprise Linux 10 | firefox | Not affected | ||
| Red Hat Enterprise Linux 10 | java-21-openjdk | Not affected | ||
| Red Hat Enterprise Linux 10 | java-25-openjdk | Not affected | ||
| Red Hat Enterprise Linux 10 | libpng | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.2 Medium
CVSS3
Связанные уязвимости
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local a ...
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive
Уязвимость библиотеки libpng, связанная с копированием буфера без проверки размера входных данных, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
6.2 Medium
CVSS3