Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2007-5266

Published: 8 October 2007

Off-by-one error in ICC profile chunk handling in the png_set_iCCP function in pngset.c in libpng before 1.0.29 beta1 and 1.2.x before 1.2.21 beta1 allows remote attackers to cause a denial of service (crash) via a crafted PNG image that prevents a name field from being NULL terminated.

Notes

AuthorNote
jdstrand
DoS on many systems
theoretically not vulnerable because the affected code uses
png_strncpy with bad args, but our versions use png_strcpy.  TODO:
get reproducer and/or verify png_strcpy usage
upstream did not provide reproducer. code not in existing versions
fully fixed in 1.2.22

Priority

Medium

Status

Package Release Status
libpng
Launchpad, Ubuntu, Debian
dapper Not vulnerable
(code not in current version)
edgy Not vulnerable
(code not in current version)
feisty Not vulnerable
(code not in current version)
gutsy Not vulnerable
(code not in current version)
upstream
Released (1.0.29 beta1 and 1.2.22)