Novell Home

CVE-2009-0749

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2009-0749 at MITRE

Description

Use-after-free vulnerability in the GIFReadNextExtension function in lib/pngxtern/gif/gifread.c in OptiPNG 0.6.2 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a crafted GIF image that causes the realloc function to return a new pointer, which triggers memory corruption when the old pointer is accessed.

NVD CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)

Novell/SUSE information

Novell Bugzilla entry: 479067, 505103

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 10.3
  • optipng >= 0.6.2-2.3
openSUSE 10.3
  • optipng >= 0.6.2-2.1

© 2012 Novell