PT-2009-1077 · Libpng · Libpng

Published

2009-02-20

·

Updated

2018-10-11

·

CVE-2008-6218

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libpng versions prior to 1.2.33 rc02 libpng versions prior to 1.4.0 beta36 libpng versions prior to 1.2.35
Description The issue is related to a memory leak in the png handle tEXt function in pngrutil.c, which allows context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted PNG file. Multiple vulnerabilities in the libpng package can lead to disruption of protected information availability, and exploitation can be done remotely.
Recommendations For libpng versions prior to 1.2.33 rc02, update to version 1.2.33 rc02 or later. For libpng versions prior to 1.4.0 beta36, update to version 1.4.0 beta36 or later. For libpng versions prior to 1.2.35, update to version 1.2.35 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09372
CVE-2008-6218
DSA-1750-1

Affected Products

Libpng