OptiPNG Use-After-Free Remote Code Execution Vulnerability
BID:55566
Info
OptiPNG Use-After-Free Remote Code Execution Vulnerability
| Bugtraq ID: | 55566 |
| Class: | Unknown |
| CVE: |
CVE-2012-4432 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2012 12:00AM |
| Updated: | May 07 2015 05:11PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
OptiPNG OptiPNG 0.7.2 OptiPNG OptiPNG 0.7.1 OptiPNG OptiPNG 0.7 Gentoo Linux |
| Not Vulnerable: |
OptiPNG OptiPNG 0.7.3 |
Discussion
OptiPNG Use-After-Free Remote Code Execution Vulnerability
OptiPNG is prone to a remote code-execution vulnerability.
Successful exploits will allow attackers to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.
OptiPNG versions 0.7 ,0.7.1 and 0.7.2 are vulnerable.
OptiPNG is prone to a remote code-execution vulnerability.
Successful exploits will allow attackers to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.
OptiPNG versions 0.7 ,0.7.1 and 0.7.2 are vulnerable.
Exploit / POC
OptiPNG Use-After-Free Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
OptiPNG Use-After-Free Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
OptiPNG Use-After-Free Remote Code Execution Vulnerability
References:
References:
- OptiPNG: Advanced PNG Optimizer (OptiPNG)