CVE-2006-5793
The sPLT chunk handling code (png_set_sPLT function in pngset.c) in libpng 1.0.6 through 1.2.12 uses a sizeof operator on the wrong data type, which allows context-dependent attackers to cause a denial of service (crash) via malformed sPLT chunks that trigger an out-of-bounds read.
- Greg Roelofs Libpng
- = 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.7rc1, 1.2.8, 1.2.9, 1.2.10, 1.2.11, 1.2.12
- CVSS 2.0
- 2.6 LOW
- EPSS
- 1.7% (75th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2006-11-17
CVE-2006-5793 at NVD
1 known exploit for CVE-2006-5793
Proof-of-concept code and exploit modules indexed by Sploitus