VulnerabilityModified
CVE-2007-5268
pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG image.
MEDIUM 4.3EPSS 3.09%
Does this matter?
Lower severity and a low EPSS score (3.09%). Track it; it rarely justifies an emergency change on its own.
Description
pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG image.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 3.09% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- libpng/libpng · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://android-developers.blogspot.com/2008/03/android-sdk-update-m5-rc15-released.htmlThird Party Advisory
- http://bugs.gentoo.org/show_bug.cgi?id=195261Third Party Advisory
- http://docs.info.apple.com/article.html?artnum=307562Third Party Advisory
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/27093Third Party Advisory
- http://secunia.com/advisories/27284Third Party Advisory
- http://secunia.com/advisories/27405Third Party Advisory
- http://secunia.com/advisories/27529Third Party Advisory
- http://secunia.com/advisories/27629Third Party Advisory
- http://secunia.com/advisories/27746Third Party Advisory
- http://secunia.com/advisories/29420Third Party Advisory
- http://secunia.com/advisories/30161Third Party Advisory
- http://secunia.com/advisories/30430Third Party Advisory
- http://secunia.com/advisories/35302Third Party Advisory
- http://secunia.com/advisories/35386Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.520323Third Party Advisory
- http://sourceforge.net/mailarchive/forum.php?thread_name=3.0.6.32.20071004082318.012a7628%40mail.comcast.net&forum_name=png-mng-implementPatch, Third Party Advisory
- http://sourceforge.net/mailarchive/message.php?msg_name=5122753600C3E94F87FBDFFCC090D1FF0400EBC5%40MERCMBX07.na.sas.comThird Party Advisory
- http://sourceforge.net/mailarchive/message.php?msg_name=e56ccc8f0709140846k24e9a040r81623783b6b1c00f%40mail.gmail.comPatch, Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-259989-1Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020521.1-1Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2009-208.htmThird Party Advisory
- http://www.coresecurity.com/?action=item&id=2148Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200711-08.xmlThird Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200805-07.xmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:217Third Party Advisory
- http://www.securityfocus.com/archive/1/483582/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/489135/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/25956Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.