CVE-2011-3328
The png_handle_cHRM function in pngrutil.c in libpng 1.5.4, when color-correction support is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed PNG image containing a cHRM chunk associated with a certain zero value.
- Affected products
- Libpng
- Greg Roelofs Libpng
- = 1.5.4
- Fix
- Available
- CVSS 2.0
- 2.6 LOW
- EPSS
- 3.8% (89th percentile)
- NVD status
- Modified
- Published
- 2012-01-17
CVE-2011-3328 at NVD
No indexed exploits for CVE-2011-3328 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2011-3328 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.