Описание
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.
A flaw was found in libpng. This buffer overflow vulnerability allows a local attacker to cause a denial of service (DoS) by exploiting the png_create_read_struct() function. This can lead to the affected system becoming unresponsive or crashing.
Отчет
This is a MODERATE impact vulnerability affecting libpng versions 1.6.43-1.6.46. A local attacker can exploit a buffer overflow in the png_create_read_struct() function, leading to a denial of service. Exploitation requires the attacker to have local access to the system and provide a specially crafted PNG file.
For java-17-openjdk-headless and java-21-openjdk-headless, while the affected code is present in the bundled sources, it is not exercised by these headless packages.
Меры по смягчению последствий
To mitigate the risk of denial of service, users should avoid processing untrusted PNG image files with applications that utilize libpng. Exercise caution when opening or viewing PNG files from unknown or suspicious sources.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of OpenJDK 11 ELS | java-11-openjdk | Fix deferred | ||
| Red Hat build of OpenJDK 11 ELS | java-11-openjdk-portable | Fix deferred | ||
| Red Hat build of OpenJDK 17 | java-17-openjdk-portable | Fix deferred | ||
| Red Hat build of OpenJDK 1.8 | java-1.8.0-openjdk-portable | Fix deferred | ||
| Red Hat build of OpenJDK 21 | java-21-openjdk-portable | Fix deferred | ||
| Red Hat build of OpenJDK 25 | java-25-openjdk-portable | Fix deferred | ||
| Red Hat Enterprise Linux 10 | firefox | Fix deferred | ||
| Red Hat Enterprise Linux 10 | java-21-openjdk | Fix deferred | ||
| Red Hat Enterprise Linux 10 | java-25-openjdk | Fix deferred | ||
| Red Hat Enterprise Linux 10 | libpng | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS3
Связанные уязвимости
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local a ...
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.
Уязвимость библиотеки libpng, связанная с копированием буфера без проверки размера входных данных, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5 Medium
CVSS3