PT-2009-3363 · Optipng · Optipng
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OptiPNG versions 0.6.2 and earlier
Description
The issue is related to a use-after-free vulnerability in the GIFReadNextExtension function, which can cause memory corruption when accessing an old pointer after the realloc function returns a new pointer. This can be triggered by a crafted GIF image, leading to a denial of service in the form of an application crash.
Recommendations
For OptiPNG versions 0.6.2 and earlier, update to a version later than 0.6.2 to resolve the issue. As a temporary workaround, consider avoiding the use of crafted GIF images that could trigger the realloc function to return a new pointer, thus minimizing the risk of memory corruption and application crash.
Correção
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Optipng