5
CVSSv2

CVE-2009-5063

Published: 31/08/2011 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Memory leak in the embedded_profile_len function in pngwutil.c in libpng prior to 1.2.39beta5 allows context-dependent malicious users to cause a denial of service (memory leak or segmentation fault) via a JPEG image containing an iCCP chunk with a negative embedded profile length. NOTE: this is due to an incomplete fix for CVE-2006-7244.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libpng libpng 1.2.39

libpng libpng

Vendor Advisories

libpng could be made to crash or run programs as your login if it opened a specially crafted file ...