The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a CVE-2004-0421 regression. NOTE: this is called an off-by-one error by some sources.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade media-libs/libpng. | Oct 30, 2017 | Jul 17, 2011 |
| Huawei Euleros 2_0_sp10 | — | Upgrade syslinux-nonlinuxUpgrade syslinux | Nov 11, 2024 | Jul 17, 2011 |
| Huawei Euleros 2_0_sp11 | — | Upgrade syslinuxUpgrade syslinux-nonlinux | Dec 12, 2024 | Jul 17, 2011 |
| Huawei Euleros 2_0_sp12 | — | Upgrade syslinux-nonlinuxUpgrade syslinux | Dec 12, 2024 | Jul 17, 2011 |
| Huawei Euleros 2_0_sp9 | — | Upgrade syslinux-nonlinuxUpgrade syslinux | Nov 11, 2024 | Jul 17, 2011 |
| Oracle_linux | — | Upgrade libpng-staticUpgrade libpng-develUpgrade libpng | Oct 16, 2024 | Jul 17, 2011 |
| Suse | — | Upgrade libpng12-develUpgrade libpng-devel-32bitUpgrade libpng16-16-x86-64-v3Upgrade libpng16-develUpgrade libpng16-compat-develUpgrade libpng16-16Upgrade libpng16-compat-devel-x86-64-v3Upgrade libpng12-0-x86Upgrade libpng12-compat-develUpgrade libpng15-15Upgrade libpng16-devel-x86-64-v3Upgrade libpng-develUpgrade libpng16-toolsUpgrade libpng12-0Upgrade libpng16-16-32bitUpgrade libpng12-0-32bit | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libpng12-0 | Nov 8, 2024 | Jul 17, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub