PT-2002-1065 · Libpng · Libpng

Published

2002-07-26

·

Updated

2008-09-05

·

CVE-2002-0728

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libpng versions 1.0.x before 1.0.14 libpng versions 1.2.x before 1.2.4
Description The issue affects the libpng package, allowing remote exploitation that may lead to a violation of confidentiality, integrity, and availability of protected information. A buffer overflow in the progressive reader for libpng can be triggered by a PNG data stream with more IDAT data than indicated by the IHDR chunk, causing a denial of service (crash).
Recommendations For libpng versions 1.0.x before 1.0.14, update to version 1.0.14 or later to resolve the issue. For libpng versions 1.2.x before 1.2.4, update to version 1.2.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of libpng until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08153
BDU:2015-08154
CVE-2002-0728
DSA-140

Affected Products

Libpng