Sploitus

CVE-2007-5266

1 known exploit for CVE-2007-5266

Off-by-one error in ICC profile chunk handling in the png_set_iCCP function in pngset.c in libpng before 1.0.29 beta1 and 1.2.x before 1.2.21 beta1 allows remote attackers to cause a denial of service (crash) via a crafted PNG image that prevents a name field from being NULL terminated.

Affected products
Libpng
Libpng
≤ 1.0.28, 1.2.20
CVSS 2.0
4.3 MEDIUM
EPSS
3.4% (88th percentile)
Weakness
CWE-189
NVD status
Modified
Published
2007-10-08
CVE-2007-5266 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2007-5266

Proof-of-concept code and exploit modules indexed by Sploitus