{"id":"AZL-41075","summary":"CVE-2009-5063 affecting package syslinux for versions less than libpng-1.2.39","details":"Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a JPEG image containing an iCCP chunk with a negative embedded profile length.  NOTE: this is due to an incomplete fix for CVE-2006-7244.","modified":"2026-04-21T04:29:14.432282Z","published":"2011-08-31T23:55:01Z","upstream":["CVE-2009-5063"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2009-5063"}],"affected":[{"package":{"name":"syslinux","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/syslinux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"libpng-1.2.39"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-41075.json"}}],"schema_version":"1.7.5"}