Description: A vulnerability has been reported in libpng, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an error in the "png_handle_tRNS" function in pngrutil.c. This can be exploited by tricking an application using the library to process a specially crafted PNG file containing a malformed tRNS chunk.
The vulnerability is reported in versions 0.90 through 1.2.16.
Solution: Update to version 1.0.25 or 1.2.17.
Provided and/or discovered by: Reported by the vendor.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.