CVE-2017-12652 is a critical vulnerability in libpng versions prior to 1.6.32, affecting products like NetApp Active IQ Unified Manager, where it fails to properly validate the length of chunks against user-defined limits. This vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating it can be exploited remotely without authentication or user interaction, leading to complete compromise of confidentiality, integrity, and availability. Despite its high severity and significant community discussion (10 mentions), there is currently no evidence of active exploitation, nor are public exploit tools like Metasploit, Nuclei, or ExploitDB available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.32CPE matchmatch criteria | cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP Universal Print Driver Series (PCL 6 and PostScript) - Potential Security Vulnerabilities
Jan 29, 2025libpng: does not check length of chunks against user limit
Jul 10, 2019libpng before 1.6.32 does not properly check the length of chunks against the user limit.
Jul 9, 2019