Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pngcrush | Pngcrush_project | * | 1.7.83 (including) |
Pngcrush | Ubuntu | artful | * |
Pngcrush | Ubuntu | lucid | * |
Pngcrush | Ubuntu | precise | * |
Pngcrush | Ubuntu | upstream | * |
Pngcrush | Ubuntu | utopic | * |
Pngcrush | Ubuntu | vivid | * |
Pngcrush | Ubuntu | wily | * |
Pngcrush | Ubuntu | yakkety | * |
Pngcrush | Ubuntu | zesty | * |