IT

Tracker / CVE-2007-2445

CVE-2007-2445

Medium 5.0

The png_handle_tRNS function in pngrutil.c in libpng before 1.0.25 and 1.2.x before 1.2.17 allows remote attackers to cause a denial of service (application crash) via a grayscale PNG image with a bad tRNS chunk CRC value.

Affected products and versions

png_reference_library libpng · … → 1.0.15
png_reference_library libpng · … → 1.2.16

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References