|
|
|
![]() |
Vulnerability Note VU#643140Libpng 1.5.0 png_set_rgb_to_gray() vulnerabilityOverviewLibpng-1.5.0 introduced a vulnerability in the rgb-to-gray transform function.I. DescriptionLibpng based applications that call the png_set_rgb_to_gray() function from pngrtran.c are vulnerable. Libpng versions prior to 1.5.0 are not vulnerable.II. ImpactAn attacker may cause the application to crash or execute arbitrary code as the user.III. SolutionApply an UpdateUpgrade to version 1.5.1.
Referenceshttp://sourceforge.net/mailarchive/forum.php?thread_name=002b01cbb0e2%24ae636c80%240b2a4580%24%40acm.org&forum_name=png-mng-implement Thanks to Glenn Randers-Pehrson for reporting this vulnerability. This document was written by Jared Allar.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||