FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-4432

This CVE name corresponds to:

Entered Topic
2013-03-21 optipng -- use-after-free vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-4432
Phase Assigned(20120821)

Description

Use-after-free vulnerability in opngreduc.c in OptiPNG Hg and 0.7.x before 0.7.3 might allow remote attackers to execute arbitrary code via unspecified vectors related to "palette reduction."

References

Source Reference
MLIST [oss-security] 20120917 CVE request: OptiPNG Palette Reduction Use-After-Free Vulnerability
MLIST [oss-security] 20120917 Re: CVE request: OptiPNG Palette Reduction Use-After-Free Vulnerability
CONFIRM http://optipng.hg.sourceforge.net/hgweb/optipng/optipng/rev/f1d5d44670a2
CONFIRM http://optipng.sourceforge.net/
CONFIRM http://sourceforge.net/news/?group_id=151404
BID 55566
SECUNIA 50654
XF optipng-palette-code-execution(78743)