PT-2004-1047 · Libpng · Libpng

Publicado

2004-08-05

·

Atualizado

2018-10-12

·

CVE-2004-0597

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libpng versions 1.2.5 and earlier libpng version 1.0.6
Description The issue is related to multiple buffer overflows in libpng, which can be exploited by remote attackers via malformed PNG images. Specifically, the png handle tRNS function does not properly validate the length of transparency chunk (tRNS) data, and the png handle sBIT or png handle hIST functions do not perform sufficient bounds checking. This can lead to the execution of arbitrary code. The vulnerability can be exploited remotely, potentially disrupting the confidentiality, integrity, and availability of protected information.
Recommendations For libpng versions 1.2.5 and earlier, update to a version later than 1.2.5 to resolve the issue. For libpng version 1.0.6, update to a version later than 1.0.6 to resolve the issue. As a temporary workaround, consider restricting the use of libpng until a patch is available. Avoid using the png handle tRNS, png handle sBIT, and png handle hIST functions with untrusted PNG images until the issue is resolved.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04800
BDU:2015-10121
CVE-2004-0597
DSA-536
RHSA-2004:402

Produtos afetados

Libpng