The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a CVE-2004-0421 regression. NOTE: this is called an off-by-one error by some sources.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade media-libs/libpng. | Oct 30, 2017 | Jul 17, 2011 |
| Huawei Euleros 2_0_sp10 | — | Upgrade syslinuxUpgrade syslinux-nonlinux | Nov 11, 2024 | Jul 17, 2011 |
| Huawei Euleros 2_0_sp11 | — | Upgrade syslinux-nonlinuxUpgrade syslinux | Dec 12, 2024 | Jul 17, 2011 |
| Huawei Euleros 2_0_sp12 | — | Upgrade syslinuxUpgrade syslinux-nonlinux | Dec 12, 2024 | Jul 17, 2011 |
| Huawei Euleros 2_0_sp9 | — | Upgrade syslinux-nonlinuxUpgrade syslinux | Nov 11, 2024 | Jul 17, 2011 |
| Oracle_linux | — | Upgrade libpng-staticUpgrade libpngUpgrade libpng-devel | Oct 16, 2024 | Jul 17, 2011 |
| Suse | — | Upgrade libpng12-0-32bitUpgrade sap-aio-releaseUpgrade libpng12-compat-develUpgrade libpng-x86Upgrade libpng14-14Upgrade libpng-develUpgrade libpng14-develUpgrade libpng14-compat-develUpgrade libpng12-0Upgrade libpng-32bitUpgrade libpng14-compat-devel-32bitUpgrade libpng-64bitUpgrade libpng14-devel-32bitUpgrade libpng12-compat-devel-32bitUpgrade libpng-devel-32bitUpgrade libpng12-devel-32bitUpgrade libpng14-14-32bitUpgrade libpngUpgrade libpng12-develUpgrade libpng-devel-64bit | Dec 12, 2013 | Jul 17, 2011 |
| Ubuntu | — | Upgrade libpng12-0 | Nov 8, 2024 | Jul 17, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub