CVE-2009-5063

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/08/2011
Last modified:
11/04/2025

Description

Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a JPEG image containing an iCCP chunk with a negative embedded profile length. NOTE: this is due to an incomplete fix for CVE-2006-7244.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* 1.2.38 (including)
cpe:2.3:a:libpng:libpng:1.2.39:-:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.2.39:beta1:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.2.39:beta2:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.2.39:beta3:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.2.39:beta4:*:*:*:*:*:*