Use-after-free vulnerability in opngreduc.c in OptiPNG Hg and 0.7.x before 0.7.3 might allow remote attackers to execute arbitrary code via unspecified vectors related to "palette reduction."
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/55566 | vdb entry |
http://optipng.sourceforge.net/ | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/78743 | vdb entry |
http://www.openwall.com/lists/oss-security/2012/09/17/5 | mailing list exploit patch |
http://optipng.hg.sourceforge.net/hgweb/optipng/optipng/rev/f1d5d44670a2 | exploit |
http://secunia.com/advisories/50654 | third party advisory vendor advisory |
http://sourceforge.net/news/?group_id=151404 | |
http://www.openwall.com/lists/oss-security/2012/09/18/2 | mailing list exploit patch |