imPC@ndo IT

Tracker / CVE-2010-2249

CVE-2010-2249

Medium 6.5

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.

Affected products and versions

apple iphone_os · 2.0 → 4.1
apple itunes · … → 10.2
apple safari · … → 5.0.4
apple tvos · … → 4.1.0
canonical ubuntu_linux
debian debian_linux
fedoraproject fedora
libpng libpng · … → 1.2.44
libpng libpng · 1.4.0 → 1.4.3
opensuse opensuse
suse linux_enterprise_server
vmware player · 2.5 → 2.5.5
vmware player · 3.1 → 3.1.2
vmware workstation · 6.5.0 → 6.5.5
vmware workstation · 7.1 → 7.1.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References