PT-2004-1049 · Libpng · Libpng

Chris Evans

·

Published

2004-08-05

·

Updated

2017-10-11

·

CVE-2004-0599

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libpng versions 1.2.5 and earlier
Description The issue concerns multiple integer overflows in libpng, specifically in the png read png function, png handle sPLT functions, and the progressive display image reading capability. These overflows can be exploited remotely via a malformed PNG image, potentially leading to a denial of service (application crash) and compromising the confidentiality, integrity, and availability of protected information.
Recommendations For libpng versions 1.2.5 and earlier, consider updating to a version that addresses these integer overflows to prevent potential crashes and information compromise. As a temporary workaround, restrict the handling of PNG images from untrusted sources to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-04800
CVE-2004-0599
DSA-536
DSA-570-1
DSA-571-1
RHSA-2004:402

Affected Products

Libpng