Junglewise Threat Intelligence

CVE-2020-28248: png-img integer overflow in image size handling

CVE-2020-28248 · Severity: low · CVSS 3.1 · Published 2021-12-10

Vendors: npm.

Executive brief

png-img is a Node.js library for manipulating PNG image files. An integer overflow in its memory allocation logic allows attackers to craft malicious PNG files that trigger a heap buffer overflow, potentially leading to code execution when a user or application loads the file.

Technical details

An integer overflow occurs in the PngImg::InitStorage_() function when calculating heap buffer size based on image dimensions (height × rowbytes). This under-allocation allows a subsequent write operation to overflow the buffer. The vulnerability is triggered by loading a crafted PNG file and requires no authentication or special privileges. A successful exploit can achieve arbitrary code execution. The vulnerability was fixed in version 3.1.0.

Affected products

  • gemini-testing png-img before 3.1.0

Timeline

  • 2021-02-20: disclosed
  • 2021-07-26: patched: Fix released in version 3.1.0
  • 2021-12-10: advisory

References