7.8
CVSSv3

CVE-2017-1000229

Published: 17/11/2017 Updated: 06/05/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an malicious user to remotely execute code or cause denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

optipng project optipng 0.7.6

debian debian linux 7.0

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

OptiPNG could be made to crash or run programs as your login if it opened a specially crafted file ...
Debian Bug report logs - #882032 optipng: CVE-2017-1000229: Integer Overflow Bug while parsing TIFF input file Package: src:optipng; Maintainer for src:optipng is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 17 Nov 2017 1 ...
Debian Bug report logs - #878839 optipng: CVE-2017-16938: global-buffer-overflow bug while parsing GIF file Package: optipng; Maintainer for optipng is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Source for optipng is src:optipng (PTS, buildd, popcon) Reported by: Joonun Jang <joonunjang ...
Two vulnerabilities were discovered in optipng, an advanced PNG optimizer, which may result in denial of service or the execution of arbitrary code if a malformed file is processed For the oldstable distribution (jessie), these problems have been fixed in version 075-1+deb8u2 For the stable distribution (stretch), these problems have been fixed ...
An integer overflow flaw leading to heap memory corruption was found in the way OptiPNG handles processing of TIFF files This flaw could potentially be used to crash the OptiPNG program by tricking it into processing crafted TIFF files ...