png-img@2.2.1 vulnerabilities

PNG Image

Direct Vulnerabilities

Known vulnerabilities in the png-img package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Buffer Overflow

png-img is a PNG Image

Affected versions of this package are vulnerable to Buffer Overflow via the PngImg::InitStorage_() function. It leads to an under-allocation of heap memory and subsequently an exploitable heap-based buffer overflow when loading a crafted PNG file.

How to fix Buffer Overflow?

Upgrade png-img to version 3.1.0 or higher.

<3.1.0