Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-64505

Опубликовано: 24 нояб. 2025
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51.

A heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access.

Отчет

This vulnerability is rated Moderate for Red Hat products. It affects applications that process specially crafted PNG files using the vulnerable libpng library. Exploitation requires user interaction, where a victim must open or process a malicious PNG image, leading to a heap buffer over-read. This could result in information disclosure or application crash. java-*-openjdk-headless packages do not contain libsplashscreen.so, hence are not affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of OpenJDK 11 ELSjava-11-openjdkFix deferred
Red Hat build of OpenJDK 11 ELSjava-11-openjdk-portableFix deferred
Red Hat build of OpenJDK 11 ELSjava-21-openjdk-portableFix deferred
Red Hat build of OpenJDK 17java-17-openjdk-portableFix deferred
Red Hat build of OpenJDK 17java-21-openjdk-portableFix deferred
Red Hat build of OpenJDK 1.8java-1.8.0-openjdk-portableFix deferred
Red Hat build of OpenJDK 21java-21-openjdk-portableFix deferred
Red Hat build of OpenJDK 21java-21-openjdk-portable-rhel7Fix deferred
Red Hat Enterprise Linux 10firefoxFix deferred
Red Hat Enterprise Linux 10java-21-openjdkFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2416905libpng: LIBPNG heap buffer overflow via malformed palette index

EPSS

Процентиль: 7%
0.00026
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
4 месяца назад

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51.

CVSS3: 6.1
nvd
4 месяца назад

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51.

CVSS3: 6.1
msrc
4 месяца назад

LIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette index

CVSS3: 6.1
debian
4 месяца назад

LIBPNG is a reference library for use in applications that read, creat ...

suse-cvrf
17 дней назад

Security update for libpng15

EPSS

Процентиль: 7%
0.00026
Низкий

4.4 Medium

CVSS3