Integer overflow in OptiPNG and Debian Linux - CVE-2017-1000229
Published: November 17, 2017 / Updated: August 8, 2020
Vulnerability identifier: #VU37894
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1000229
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.
Affected software
OptiPNG
Debian Linux
Gentoo Linux
Fedora
optipng
Debian Linux
Gentoo Linux
Fedora
optipng
How to mitigate CVE-2017-1000229
Install update from vendor's website.
optipng - addressed in versions 0.7.6-5.fc27, 0.7.6-6.el6, 0.7.6-6.fc25, 0.7.6-6.fc26