Sploitus

CVE-2006-5793

1 known exploit for CVE-2006-5793

The sPLT chunk handling code (png_set_sPLT function in pngset.c) in libpng 1.0.6 through 1.2.12 uses a sizeof operator on the wrong data type, which allows context-dependent attackers to cause a denial of service (crash) via malformed sPLT chunks that trigger an out-of-bounds read.

Affected products
Red Hat, Libpng
Greg Roelofs Libpng
= 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.7rc1, 1.2.8, 1.2.9, 1.2.10, 1.2.11, 1.2.12
CVSS 2.0
2.6 LOW
EPSS
1.7% (75th percentile)
Weakness
CWE-20
NVD status
Modified
Published
2006-11-17
CVE-2006-5793 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2006-5793

Proof-of-concept code and exploit modules indexed by Sploitus