Integer overflow in the png_set_unknown_chunks function...
Moderate severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Jun 9, 2025
Description
Published by the National Vulnerability Database
May 6, 2014
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Jun 9, 2025
Integer overflow in the png_set_unknown_chunks function in libpng/pngset.c in libpng before 1.5.14beta08 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a crafted image, which triggers a heap-based buffer overflow.
References