Buffer Overflow Affecting png-img package, versions <3.1.0
Threat Intelligence
EPSS
0.45% (76th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-PNGIMG-1078233
- published 21 Feb 2021
- disclosed 21 Feb 2021
- credit Unknown
How to fix?
Upgrade png-img
to version 3.1.0 or higher.
Overview
png-img is a PNG Image
Affected versions of this package are vulnerable to Buffer Overflow via the PngImg::InitStorage_()
function. It leads to an under-allocation of heap memory and subsequently an exploitable heap-based buffer overflow when loading a crafted PNG file.
References
CVSS Scores
version 3.1