CVE-2011-3464
Off-by-one error in the png_formatted_warning function in pngerror.c in libpng 1.5.4 through 1.5.7 might allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified vectors, which trigger a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Off-by-one error in the png_formatted_warning function in pngerror.c in libpng 1.5.4 through 1.5.7 might allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified vectors, which trigger a stack-based buffer overflow.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 3.13% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- libpng/libpng
- Source
- product-security@apple.com
References
- http://secunia.com/advisories/47827Vendor Advisory
- http://secunia.com/advisories/49660Vendor Advisory
- http://security.gentoo.org/glsa/glsa-201206-15.xml
- http://www.libpng.org/pub/png/libpng.html
- http://secunia.com/advisories/47827Vendor Advisory
- http://secunia.com/advisories/49660Vendor Advisory
- http://security.gentoo.org/glsa/glsa-201206-15.xml
- http://www.libpng.org/pub/png/libpng.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.