« List of all CVEs

CVE-2011-2691

Published: 7/17/2011 Last updated: 8/6/2024 Reserved: 7/11/2011

The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function call using a NULL pointer argument instead of an empty-string argument, which allows remote attackers to cause a denial of service (application crash) via a crafted PNG image.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (4)

conf-gd conf-libpng grib qrencode

Products affected (1)

Product Vendor Version
n/a n/a < 10.2.31-3.25.1

References (36)