Memory Leak in LodePNG Affecting WinPR and Related Products
CVE-2019-17178

7.5HIGH

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
4 October 2019

What is CVE-2019-17178?

A memory leak exists in the HuffmanTree_makeFromFrequencies function within lodepng.c of LodePNG, which is utilized by FreeRDP and similar products. This issue arises when the realloc pointer is incorrectly managed, leading to inefficient memory usage and potential resource exhaustion. Developers using affected versions are advised to review their code and apply relevant patches to mitigate this vulnerability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.