CVE-2016-10087

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
30/01/2017
Last modified:
20/04/2025

Description

The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allows context-dependent attackers to cause a NULL pointer dereference vectors involving loading a text chunk into a png structure, removing the text, and then adding another text chunk to the structure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libpng:libpng:0.8:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:0.71:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:0.81:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:0.82:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:0.85:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:0.86:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:0.87:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:0.88:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:0.89:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:0.89c:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:0.90:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:0.95:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:0.96:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:0.97:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:0.98:*:*:*:*:*:*:*