CVE-2017-12652
Critical
CVE-2017-12652
libpng before 1.6.32 does not properly check the length of chunks against the user limit.
Exploit probability
4.1%
Published
July 10, 2019
Required by
Not available
Last source change
August 7, 2026
02 / AFFECTED SOFTWARE
Affected packages
750 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2017-12652
View original source
libpng before 1.6.32 does not properly check the length of chunks against the user limit.
05 / REFERENCES
Further evidence
- http://www.securityfocus.com/bid/109269
- https://github.com/glennrp/libpng/blob/df7e9dae0c4aac63d55361e35709c864fa1b8363/ANNOUNCE
- https://github.com/pnggroup/libpng/commit/347538efbdc21b8df684ebd92d37400b3ce85d55
- https://security.netapp.com/advisory/ntap-20220506-0003/
- https://support.f5.com/csp/article/K88124225
- https://support.f5.com/csp/article/K88124225?utm_source=f5support&%3Butm_medium=RSS
- https://support.f5.com/csp/article/K88124225?utm_source=f5support&utm_medium=RSS