|
|
|
Vulnerability Note VU#477512libpng png_handle_sPLT() integer overflowOverviewThe Portable Network Graphics library (libpng) contains a flaw that could introduce a remotely exploitable vulnerability.I. DescriptionThe Portable Network Graphics (PNG) image format is used as an alternative to other image formats such as the Graphics Interchange Format (GIF). The libpng reference library is available for application developers to support the PNG image format.A potential integer overflow error exists during a memory allocation within the png_handle_sPLT() function. While the code that contains this error introduces a dangerous condition, it is unclear what practical vulnerabilities it might present in applications using libpng.
References
Thanks to Chris Evans for reporting this vulnerability. This document was written by Chad Dougherty and Damon Morda.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||