OptiPNG: User-assisted execution of arbitrary code A use-after-free error in OptiPNG could result in execution of arbitrary code or Denial of Service. optipng 2014-04-07 2014-04-07 435340 remote 0.7.3 0.7.3

OptiPNG is a PNG optimizer that recompresses image files to a smaller size, without losing any information.

A use-after-free vulnerability exists in the palette reduction functionality of OptiPNG.

A remote attacker could entice a user to open a specially crafted image file, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition.

There is no known workaround at this time.

All OptiPNG users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=media-gfx/optipng-0.7.3"
CVE-2012-4432 ackle ackle