[WID-SEC-2023-0175] libpng: Schwachstelle ermöglicht Denial of Service CVSS Base Score 9.1 (kritisch) CVSS Temporal Score 8.3 (hoch) Remoteangriff ja Datum 13.12.2015 Stand UPDATE 25.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux MacOS X Sonstiges UNIX Windows Produktbeschreibung Die libpng ist die offizielle Referenzbibliothek für die Darstellung und Manipulation von Bilder im Portable Network Graphics (PNG) Format. Produkte UPDATE 30.06.2025 Dell NetWorker <19.13 Dell NetWorker <19.11.0.5 UPDATE 01.09.2024 HCL Notes UPDATE 23.01.2023 Amazon Linux 2 UPDATE 30.03.2017 SUSE Linux UPDATE 13.01.2016 Debian Linux UPDATE 06.01.2016 Ubuntu Linux 13.12.2015 Open Source libpng <1.6.0 Open Source libpng <1.5.26 Open Source libpng <1.4.19 Open Source libpng <1.2.56 Open Source libpng <1.0.66 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in libpng ausnutzen, um einen Denial of Service Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A critical (CVSS 9.1) vulnerability in libpng allows a remote, anonymous attacker to cause a denial of service. Affected versions include libpng prior to 1.6.0, 1.5.26, 1.4.19, 1.2.56, and 1.0.66. The advisory notes that mitigations are available, but specific patch versions or workarounds are not detailed in the provided text.