PT-2009-1077 · Libpng · Libpng

Publicado

2009-02-20

·

Atualizado

2018-10-11

·

CVE-2008-6218

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libpng versions prior to 1.2.33 rc02 libpng versions prior to 1.4.0 beta36 libpng versions prior to 1.2.35
Description The issue is related to a memory leak in the png handle tEXt function in pngrutil.c, which allows context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted PNG file. Multiple vulnerabilities in the libpng package can lead to disruption of protected information availability, and exploitation can be done remotely.
Recommendations For libpng versions prior to 1.2.33 rc02, update to version 1.2.33 rc02 or later. For libpng versions prior to 1.4.0 beta36, update to version 1.4.0 beta36 or later. For libpng versions prior to 1.2.35, update to version 1.2.35 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09372
CVE-2008-6218
DSA-1750-1

Produtos afetados

Libpng