SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-0597

Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of…

HIGH 10.0EPSS 82.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 82.5%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
82.54% probability · 100th percentile
CISA KEV
Not listed
Affected
greg roelofs/libpng · microsoft/msn messenger · microsoft/windows media player · microsoft/windows messenger · microsoft/windows 98se · microsoft/windows me
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.