Sploitus

CVE-2007-5267

1 known exploit for CVE-2007-5267

Off-by-one error in ICC profile chunk handling in the png_set_iCCP function in pngset.c in libpng before 1.2.22 beta1 allows remote attackers to cause a denial of service (crash) via a crafted PNG image, due to an incorrect fix for CVE-2007-5266.

Affected products
Libpng
Libpng
≤ 1.2.21
CVSS 2.0
4.3 MEDIUM
EPSS
2.0% (78th percentile)
Weakness
CWE-189
NVD status
Modified
Published
2007-10-08
CVE-2007-5267 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2007-5267

Proof-of-concept code and exploit modules indexed by Sploitus