libpng DoS / crash in png_set_iCCP
Published Oct 8, 2007
4.3
MEDIUMCVSS 2.0
EPSS 3.42%
Description
Off-by-one error in ICC profile chunk handling in the png_set_iCCP function in pngset.c in libpng before 1.0.29 beta1 and 1.2.x before 1.2.21 beta1 allows remote attackers to cause a denial of service (crash) via a crafted PNG image that prevents a name field from being NULL terminated.
Affected products
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of libpng and libpng10 as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.42% (0.03423) | 88.51th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.42% (0.03423) | 87.32th | v5 (v2026.06.15) |
| Apr 17, 2026 | 11.78% (0.11784) | 93.73th | v4 (v2025.03.14) |
| Jun 8, 2025 | 13.05% (0.13047) | 93.70th | v4 (v2025.03.14) |
| Mar 30, 2025 | 14.79% (0.14790) | 93.94th | v4 (v2025.03.14) |
| Mar 29, 2025 | 17.58% (0.17578) | 91.90th | v4 (v2025.03.14) |
| Mar 17, 2025 | 14.79% (0.14790) | 94.00th | v4 (v2025.03.14) |
| Dec 17, 2024 | 3.19% (0.03185) | 90.95th | v3 (v2023.03.01) |
| Dec 12, 2024 | 2.17% (0.02172) | 89.77th | v3 (v2023.03.01) |
| Jul 4, 2024 | 2.31% (0.02308) | 89.79th | v3 (v2023.03.01) |
| Mar 11, 2024 | 2.51% (0.02515) | 89.84th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.42% (0.02419) | 88.22th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.93% (0.03932) | 85.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.93% (0.03932) | 84.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.93% (0.03932) | 67.70th | v2 (v2022.01.01) |
References (37)
- http://android-developers.blogspot.com/2008/03/android-sdk-update-m5-rc15-released.html x_refsource_CONFIRMThird Party Advisory
- http://bugs.gentoo.org/show_bug.cgi?id=195261 x_refsource_CONFIRMThird Party Advisory
- http://docs.info.apple.com/article.html?artnum=307562 x_refsource_CONFIRMThird Party Advisory
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.html vendor-advisoryx_refsource_APPLEMailing ListThird Party Advisory
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html vendor-advisoryx_refsource_APPLEMailing ListThird Party Advisory
- http://secunia.com/advisories/27284 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/27529 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/27629 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/27746 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/29420 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/30161 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/30430 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35302 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35386 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.520323 vendor-advisoryx_refsource_SLACKWAREThird Party Advisory
- http://sourceforge.net/mailarchive/forum.php?thread_name=5122753600C3E94F87FBDFFCC090D1FF0400EA68%40MERCMBX07.na.sas.com&forum_name=png-mng-implement mailing-listx_refsource_MLISTThird Party Advisory
- http://sourceforge.net/mailarchive/message.php?msg_name=e56ccc8f0709140846k24e9a040r81623783b6b1c00f%40mail.gmail.com mailing-listx_refsource_MLISTThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-259989-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020521.1-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://support.avaya.com/elmodocs2/security/ASA-2009-208.htm x_refsource_CONFIRMThird Party Advisory
- http://www.coresecurity.com/?action=item&id=2148 x_refsource_MISCThird Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200711-08.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:217 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.securityfocus.com/archive/1/483582/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/489135/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/25957 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.us-cert.gov/cas/techalerts/TA08-150A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2008/0924/references vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2008/1697 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2009/1462 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2009/1560 vdb-entryx_refsource_VUPENThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2007-5266 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=324711 Issue Tracking
- https://issues.rpath.com/browse/RPL-1814 x_refsource_CONFIRMBroken Link
- https://nvd.nist.gov/vuln/detail/CVE-2007-5266
- https://www.cve.org/CVERecord?id=CVE-2007-5266
Change history (0)
No recorded changes yet.