PT-2020-16804 · Pngcheck+3 · Pngcheck+3

Published

2020-12-06

·

Updated

2024-06-15

·

CVE-2020-27818

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions pngcheck version 2.4.0
Description A flaw was found in the check chunk name() function. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.
Recommendations For pngcheck version 2.4.0, consider disabling the check chunk name() function until a patch is available to prevent potential denial of service attacks.

Fix

DoS

Out of bounds Read

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27818
DLA-3032-1
OPENSUSE-SU-2020:2177-1
OPENSUSE-SU-2020:2198-1
OPENSUSE-SU-2020:2220-1
OPENSUSE-SU-2020:2227-1
OPENSUSE-SU-2020_2177-1
OPENSUSE-SU-2020_2198-1
OPENSUSE-SU-2024:11176-1
USN-6182-1

Affected Products

Linuxmint
Suse
Ubuntu
Pngcheck