Candidate: CVE-2012-4432 PublicDate: 2012-10-01 03:26:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4432 Description: Use-after-free vulnerability in opngreduc.c in OptiPNG Hg and 0.7.x before 0.7.3 might allow remote attackers to execute arbitrary code via unspecified vectors related to "palette reduction." Ubuntu-Description: Notes: jdstrand> per upstream, introduced in 0.7 Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_optipng: upstream: http://optipng.hg.sourceforge.net/hgweb/optipng/optipng/rev/f1d5d44670a2 upstream_optipng: released (0.7.3) hardy_optipng: not-affected lucid_optipng: not-affected natty_optipng: not-affected oneiric_optipng: not-affected precise_optipng: not-affected devel_optipng: not-affected (0.6.4-1)