|
|
Log in / Subscribe / Register

optipng: code execution

Package(s):optipng CVE #(s):CVE-2016-3981 CVE-2016-3982
Created:April 18, 2016 Updated:April 20, 2016
Description: From the CVE entries:

Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file. (CVE-2016-3981)

Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file, which triggers a heap-based buffer overflow. (CVE-2016-3982)

Alerts:
Gentoo 201608-01 optipng 2016-08-10
Ubuntu USN-2951-1 optipng 2016-04-18
openSUSE openSUSE-SU-2016:1082-1 optipng 2016-04-17
openSUSE openSUSE-SU-2016:1078-1 optipng 2016-04-17

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds