CVE-2009-5063

Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a JPEG image containing an iCCP chunk with a negative embedded profile length. NOTE: this is due to an incomplete fix for CVE-2006-7244.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.2.39:-:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.2.39:beta1:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.2.39:beta2:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.2.39:beta3:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.2.39:beta4:*:*:*:*:*:*

History

07 Nov 2023, 02:04

Type Values Removed Values Added
References
  • {'url': 'http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commitdiff;h=948ee23a2a400672b1751cfc646a7467741e9b2e#patch18', 'name': 'http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commitdiff;h=948ee23a2a400672b1751cfc646a7467741e9b2e#patch18', 'tags': ['Third Party Advisory'], 'refsource': 'CONFIRM'}
  • () http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=commitdiff%3Bh=948ee23a2a400672b1751cfc646a7467741e9b2e#patch18 -

Information

Published : 2011-08-31 23:55

Updated : 2023-12-10 11:03


NVD link : CVE-2009-5063

Mitre link : CVE-2009-5063

CVE.ORG link : CVE-2009-5063


JSON object : View

Products Affected

libpng

  • libpng
CWE
CWE-401

Missing Release of Memory after Effective Lifetime