Use-after-free vulnerability in opngreduc.c in OptiPNG Hg and 0.7.x before 0.7.3 might allow remote attackers to execute arbitrary code via unspecified vectors related to "palette reduction."
| Software | From | Fixed in |
|---|---|---|
| optipng / optipng | 0.7.1 | 0.7.1.x |
| optipng / optipng | hg | hg.x |
| optipng / optipng | 0.7.0 | 0.7.0.x |
| optipng / optipng | 0.7.2 | 0.7.2.x |