CVE-2006-7244

libpng < 1.2.15beta3 - Denial of Service via Negative iCCP Profile Length

Title source: llm
STIX 2.1

Description

Memory leak in pngwutil.c in libpng 1.2.13beta1, and other versions before 1.2.15beta3, allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a JPEG image containing an iCCP chunk with a negative embedded profile length.

Scores

EPSS 0.0124
EPSS Percentile 65.8%

Details

CWE
CWE-399
Status published
Products (11)
libpng/libpng 1.0.0
libpng/libpng 1.0.1
libpng/libpng 1.0.2
libpng/libpng 1.0.3
libpng/libpng 1.0.5
libpng/libpng 1.0.6 (9 CPE variants)
libpng/libpng 1.0.7 (11 CPE variants)
libpng/libpng 1.0.8 (6 CPE variants)
libpng/libpng 1.0.9 (13 CPE variants)
libpng/libpng 1.0.10 (3 CPE variants)
... and 1 more
Published Aug 31, 2011
Tracked Since Feb 18, 2026