CVE-2007-2445

Description

From CVE.org

The png_handle_tRNS function in pngrutil.c in libpng before 1.0.25 and 1.2.x before 1.2.17 allows remote attackers to cause a denial of service (application crash) via a grayscale PNG image with a bad tRNS chunk CRC value.

Acknowledgements

Red Hat would like to thank Glenn Randers-Pehrson, Mats Palmgren, and Tavis Ormandy for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.