Skip to content

Critical Security Vulnerability: Outdated libpng 1.6.22 (CVE-2017-12652) #2186

@Tarun24RN

Description

@Tarun24RN

The library is using an outdated version of libpng (1.6.22) through the uCrop dependency, which contains critical security vulnerabilities with a CVSS score of 9.8.
Environment

react-native-image-crop-picker version: 0.42.0
React Native version: 0.78.2
Platform: Android (iOS not affected)
Build type: Release/Debug

ulnerable Library Found:

  • Library: libpng
  • Version: 1.6.22
  • Location: /config.arm64_v8a.apklib/arm64-v8a/libucrop.so
  • CVE: CVE-2017-12652
  • Severity: Critical (CVSS 9.8)

The vulnerability stems from the uCrop library (com.github.yalantis:ucrop) which bundles libpng 1.6.22. The latest safe version is libpng 1.6.32+.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions