Multiple integer overflows in libpng before 1.5.14rc03 allow remote attackers to cause a denial of service (crash) via a crafted image to the (1) pngsetsPLT or (2) pngsettext_2 function, which triggers a heap-based buffer overflow.
{ "urgency": "not yet assigned" }