PT-2004-1081 · Libpng · Libpng

CVE-2004-0421

·

Publicado

2004-04-30

·

Atualizado

2024-02-09

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libpng versions 1.0.15 and earlier libpng versions 1.0.6 and earlier libpng version 1.2.2
Description The issue allows attackers to cause a denial of service via a malformed PNG image file, triggering an error that causes an out-of-bounds read when creating the error message. Exploitation can be done remotely. It may also allow execution of arbitrary code using a specially crafted PNG file.
Recommendations For libpng versions 1.0.15 and earlier, update to a version later than 1.0.15 to resolve the issue. For libpng versions 1.0.6 and earlier, update to a version later than 1.0.6 to resolve the issue. For libpng version 1.2.2, update to a version later than 1.2.2 to resolve the issue. As a temporary workaround, consider restricting the use of libpng until a patch is available. Avoid using libpng to process untrusted PNG image files until the issue is resolved.

Correção

Out of bounds Read

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-07854
BDU:2015-07855
BDU:2015-07856
BDU:2015-07857
BDU:2015-10121
CVE-2004-0421
DSA-498
RHSA-2004:180

Produtos afetados

Libpng