Summary
The remote host is probably affected by the vulnerabilities described in CVE-2008-1382
Impact
libpng 1.0.6 through 1.0.32, 1.2.0 through 1.2.26, and 1.4.0beta01 through 1.4.0beta19 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PNG file with zero length unknown chunks, which trigger an access of uninitialized memory.
Solution
All users should upgrade to the latest libpng version of their Linux Distribution.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2008-1382 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities