>> libPNG "png_set_sPLT()" Chunk Handling Remote Denial of Service Vulnerability
Title : libPNG "png_set_sPLT()" Chunk Handling Remote Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2006-4521 CVE ID : CVE-2006-5793
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-11-15
Technical Description
A vulnerability has been identified in libPNG, which could be exploited by attackers to cause a denial of service. This flaw is due to an error in the "png_set_sPLT()" [pngset.c] function when processing a malformed PNG file, which could be exploited by attackers to crash an application linked against a vulnerable library.