GHSA-fj59-ccrm-8h5wMediumCVSS 6.5

In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function ...

Published
May 13, 2022
Last Modified
May 29, 2026

🔗 CVE IDs covered (1)

📋 Description

In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.

🔗 References (22)