Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-4432

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2012-4432
Last Modified 29 Jan 2013 11:54:52
Published 30 Sep 2012 11:26:16
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2012-4432

Summary

Use-after-free vulnerability in opngreduc.c in OptiPNG Hg and 0.7.x before 0.7.3 might allow remote attackers to execute arbitrary code via unspecified vectors related to "palette reduction."

Vulnerable Systems

Application

  • Optipng 0.7.0

  • Optipng 0.7.1

  • Optipng 0.7.2

  • Optipng Hg


References

XF - optipng-palette-code-execution(78743)

MLIST - [oss-security] 20120917 Re: CVE request: OptiPNG Palette Reduction Use-After-Free Vulnerability

MLIST - [oss-security] 20120917 CVE request: OptiPNG Palette Reduction Use-After-Free Vulnerability

CONFIRM - http://sourceforge.net/news/?group_id=151404

SECUNIA - 50654

CONFIRM - http://optipng.sourceforge.net/

CONFIRM - http://optipng.hg.sourceforge.net/hgweb/optipng/optipng/rev/f1d5d44670a2

BID - 55566


Last Updated: 27 May 2016 11:00:49