Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-28164

Опубликовано: 27 янв. 2026
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.

A flaw was found in libpng. This buffer overflow vulnerability allows a local attacker to cause a denial of service (DoS) by exploiting the png_create_read_struct() function. This can lead to the affected system becoming unresponsive or crashing.

Отчет

This is a MODERATE impact vulnerability affecting libpng versions 1.6.43-1.6.46. A local attacker can exploit a buffer overflow in the png_create_read_struct() function, leading to a denial of service. Exploitation requires the attacker to have local access to the system and provide a specially crafted PNG file. For java-17-openjdk-headless and java-21-openjdk-headless, while the affected code is present in the bundled sources, it is not exercised by these headless packages.

Меры по смягчению последствий

To mitigate the risk of denial of service, users should avoid processing untrusted PNG image files with applications that utilize libpng. Exercise caution when opening or viewing PNG files from unknown or suspicious sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of OpenJDK 11 ELSjava-11-openjdkFix deferred
Red Hat build of OpenJDK 11 ELSjava-11-openjdk-portableFix deferred
Red Hat build of OpenJDK 17java-17-openjdk-portableFix deferred
Red Hat build of OpenJDK 1.8java-1.8.0-openjdk-portableFix deferred
Red Hat build of OpenJDK 21java-21-openjdk-portableFix deferred
Red Hat build of OpenJDK 25java-25-openjdk-portableFix deferred
Red Hat Enterprise Linux 10firefoxFix deferred
Red Hat Enterprise Linux 10java-21-openjdkFix deferred
Red Hat Enterprise Linux 10java-25-openjdkFix deferred
Red Hat Enterprise Linux 10libpngFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2433398libpng: libpng: Denial of Service via buffer overflow in png_create_read_struct() function

EPSS

Процентиль: 4%
0.00139
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
6 месяцев назад

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.

CVSS3: 5.5
nvd
6 месяцев назад

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.

CVSS3: 5.5
debian
6 месяцев назад

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local a ...

CVSS3: 5.5
github
6 месяцев назад

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.

CVSS3: 5.5
fstec
6 месяцев назад

Уязвимость библиотеки libpng, связанная с копированием буфера без проверки размера входных данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 4%
0.00139
Низкий

5 Medium

CVSS3