PT-2008-1054 · Libpng+1 · Libpng+1

Tavis Ormandy

·

Publicado

2008-04-14

·

Atualizado

2020-01-17

·

CVE-2008-1382

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libpng versions 1.0.6 through 1.0.32 libpng versions 1.2.0 through 1.2.26 libpng versions 1.4.0beta01 through 1.4.0beta19
Description The issue allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a PNG file with zero length "unknown" chunks, which trigger an access of uninitialized memory. Exploitation of the vulnerabilities may lead to a violation of confidentiality, integrity, and availability of protected information and can be carried out remotely.
Recommendations For libpng versions 1.0.6 through 1.0.32, update to a version outside of this range to mitigate the risk. For libpng versions 1.2.0 through 1.2.26, update to a version outside of this range to mitigate the risk. For libpng versions 1.4.0beta01 through 1.4.0beta19, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting the use of libpng until a patch is available. Avoid using libpng to process untrusted PNG files until the issue is resolved.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06312
BDU:2015-06315
BDU:2015-08406
BDU:2015-08407
BDU:2015-09632
BDU:2015-10121
CVE-2008-1382
RHSA-2009:0333
RHSA-2009_0333

Produtos afetados

Red Hat
Libpng