|
|
| |
|
| |
libpng: resource consumption
| Package(s): | libpng10 |
CVE #(s): | CVE-2010-0205
|
| Created: | March 16, 2010 |
Updated: | October 6, 2010 |
| Description: |
From the Red Hat bugzilla:
It was reported that libpng suffers from an issue where certain highly
compressed ancillary chunks (zTxt, iTxt, iCCP) could cause libpng to stall or crash by consuming huge amounts of memory. This vulnerability is reported to affect all versions of libpng prior to 1.4.1, as well as versions of Firefox from 3.0. It is also possible that other gecko-based browsers are vulnerable as well, as well as all versions of pngcrush, ImageMagick, and GraphicsMagick. |
| Alerts: |
|
( Log in to post comments)
|
|
|