Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The png_handle_tRNS function in pngrutil.c in libpng before 1.0.25 and 1.2.x before 1.2.17 allows remote attackers to cause a denial of service (application crash) via a grayscale PNG image with a bad tRNS chunk CRC value.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Libpng库远程拒绝服务漏洞
Vulnerability Description
libpng是多种应用程序使用的解析PNG图象格式的库。 libpng库在处理PNG文件中畸形结构时存在漏洞,攻击者可能通过诱使用户处理恶意图形文件导致客户端采用libpng的应用程序崩溃。 libpng中png_ptr->num_trans被设置为1,在检查完CRC后存在一个错误返回,因此从未分配trans[]数组。由于png_ptr->num_trans非0,libpng之后会试图使用这个数组。如果用户诱骗用户打开了包含有畸形tRNS块的灰度PNG图形的话,就会导致某些libpng应用程序崩溃。
CVSS Information
N/A
Vulnerability Type
N/A