CVE-2011-2691

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
17/07/2011
Last modified:
11/04/2025

Description

The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function call using a NULL pointer argument instead of an empty-string argument, which allows remote attackers to cause a denial of service (application crash) via a crafted PNG image.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* 1.0.0 (including) 1.0.55 (excluding)
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* 1.2.0 (including) 1.2.45 (excluding)
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* 1.4.0 (including) 1.4.8 (excluding)
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* 1.5.0 (including) 1.5.4 (excluding)
cpe:2.3:o:fedoraproject:fedora:14:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools