CVE-2006-0481 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Roelofs Libpng
Severity
5.0MEDIUMNVD
EPSS
2.1%
top 16.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 31
Latest updateMay 3
Description
Heap-based buffer overflow in the alpha strip capability in libpng 1.2.7 allows context-dependent attackers to cause a denial of service (crash) when the png_do_strip_filler function is used to strip alpha channels out of the image.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9