PT-2004-1049 · Libpng · Libpng
Chris Evans
·
Published
2004-08-05
·
Updated
2017-10-11
·
CVE-2004-0599
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libpng versions 1.2.5 and earlier
Description
The issue concerns multiple integer overflows in libpng, specifically in the
png read png function, png handle sPLT functions, and the progressive display image reading capability. These overflows can be exploited remotely via a malformed PNG image, potentially leading to a denial of service (application crash) and compromising the confidentiality, integrity, and availability of protected information.Recommendations
For libpng versions 1.2.5 and earlier, consider updating to a version that addresses these integer overflows to prevent potential crashes and information compromise. As a temporary workaround, restrict the handling of PNG images from untrusted sources to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libpng