ZeroHour

CVE-2016-2191

PoC
CVSS 3.0
6.5 medium
EPSS
4%p89
Published
()
Modified
Description

The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a crafted BMP image.

Vendors
optipngcanonicaldebianopensuse
Products
optipng, ubuntu linux, debian linux, leap, opensuse
Weakness
CWE-119
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.