Executive brief
png-img is a Node.js library for manipulating PNG image files. An integer overflow in its memory allocation logic allows attackers to craft malicious PNG files that trigger a heap buffer overflow, potentially leading to code execution when a user or application loads the file.
Technical details
An integer overflow occurs in the PngImg::InitStorage_() function when calculating heap buffer size based on image dimensions (height × rowbytes). This under-allocation allows a subsequent write operation to overflow the buffer. The vulnerability is triggered by loading a crafted PNG file and requires no authentication or special privileges. A successful exploit can achieve arbitrary code execution. The vulnerability was fixed in version 3.1.0.
Affected products
- gemini-testing png-img before 3.1.0
Timeline
- 2021-02-20: disclosed
- 2021-07-26: patched: Fix released in version 3.1.0
- 2021-12-10: advisory