CVE-2012-4432: Optipng

High severity, CVSS 7.5. EPSS: 5.2% chance of exploitation in the next 30 days.

Use-after-free vulnerability in opngreduc.c in OptiPNG Hg and 0.7.x before 0.7.3 might allow remote attackers to execute arbitrary code via unspecified vectors related to "palette reduction."

Affected products

  • Optipng Optipng: version 0.7.0 only; version 0.7.1 only; version 0.7.2 only; version hg only

Published 2012-10-01. Last modified 2026-06-16.