CVE-2020-28248
20.02.2021, 00:15
An integer overflow in the PngImg::InitStorage_() function of png-img before 3.1.0 leads to an under-allocation of heap memory and subsequently an exploitable heap-based buffer overflow when loading a crafted PNG file.Enginsight
Vendor | Product | Version |
---|---|---|
png-img_project | png-img | 𝑥 < 3.1.0 |
𝑥
= Vulnerable software versions
References