Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which triggers an out-of-bounds read.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
libpng‘png_convert_to_rfc1123()’函数内存损坏漏洞
Vulnerability Description
libpng是一个可对PNG图形文件实现创建、读写等操作的PNG参考库。 libpng的png.c文件中的‘png_convert_to_rfc1123’函数存在安全漏洞。远程攻击者可借助图像数据中特制的tIME数据块利用该漏洞获取敏感的进程内存信息。以下版本受到影响:libpng 1.0.64之前1.0.x版本,1.2.54之前1.2.x版本,1.4.17之前1.4.x版本。
CVSS Information
N/A
Vulnerability Type
N/A