Home→Descriptions→SA50654
| Secunia ID | |
| CVE-ID | |
| Release Date |
17 Sep 2012 |
| Last Change |
22 Oct 2012 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
OptiPNG 0.x |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
A vulnerability has been reported in OptiPNG, which can be exploited by malicious people to potentially compromise a user's system. The vulnerability is caused due to a use-after-free error related to the palette reduction functionality. No further information is currently available. Success exploitation may allow execution of arbitrary code. The vulnerability is reported in versions prior to 0.7.4. |
| Solution |
Update to version 0.7.4. |
| Reported by |
Reported by the vendor. |
| Original Advisory |
http://sourceforge.net/news/?group_id=151404 |