Do your applications use this vulnerable package?
Test your applications
Overview
libpng before 1.6.32 does not properly check the length of chunks against the user limit.
References
CVSS Score
9.8
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2017-12652
- CWE
- CWE-20
- Snyk ID
- SNYK-DEBIAN9-LIBPNG16-452465
- Disclosed
- 10 Jul, 2019
- Published
- 24 Jul, 2019