Buffer overflow in OptiPNG - CVE-2023-43907
Published: November 10, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in gifread.c. A remote attacker can create a specially crafted PNG image, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Fedora
openEuler
optipng
optipng-debugsource
optipng-debuginfo
How to mitigate CVE-2023-43907
optipng-debugsource - update to 0.7.8-1
optipng-debuginfo - update to 0.7.8-1
optipng - addressed in versions 0.7.8-1.el9, 0.7.8-1.fc37, 0.7.8-1.fc38, 0.7.8-1.fc39, 7.9.1-1.el9, 7.9.1-1.el10_1, 7.9.1-1.fc41, 7.9.1-1.fc42
External References
Related Security Bulletins
- Remote code execution in OptiPNG
- Fedora EPEL 9 update for optipng
- Fedora 37 update for optipng
- Fedora 38 update for optipng
- Fedora 39 update for optipng
- openEuler update for optipng
- Fedora EPEL 9 update for optipng
- Fedora EPEL 10.1 update for optipng
- Fedora 41 update for optipng
- Fedora 42 update for optipng