Unrated severityNVD Advisory· Published Jan 17, 2012· Updated Apr 29, 2026
CVE-2011-3328
CVE-2011-3328
Description
The png_handle_cHRM function in pngrutil.c in libpng 1.5.4, when color-correction support is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed PNG image containing a cHRM chunk associated with a certain zero value.
Affected products
1- cpe:2.3:a:greg_roelofs:libpng:1.5.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- libpng.org/pub/png/libpng.htmlnvdPatchVendor Advisory
- www.kb.cert.org/vuls/id/477046nvdPatchUS Government Resource
- sourceforge.net/tracker/index.phpnvdExploit
- lists.apple.com/archives/security-announce/2012/Feb/msg00000.htmlnvd
- lists.apple.com/archives/security-announce/2012/May/msg00001.htmlnvd
- lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlnvd
- support.apple.com/kb/HT5130nvd
- support.apple.com/kb/HT5281nvd
- support.apple.com/kb/HT5503nvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.