libpng possible DoS / crash
Published Oct 8, 2007
4.3
MEDIUMCVSS 2.0
EPSS 3.09%
Description
pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG image.
Affected products
No data.
Configuration 1
Configuration 2
- 6.06
- 6.10
- 7.04
- 7.10
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of libpng and libpng10 as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.09% (0.03092) | 87.27th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.09% (0.03092) | 85.98th | v5 (v2026.06.15) |
| Apr 17, 2026 | 13.70% (0.13699) | 94.28th | v4 (v2025.03.14) |
| Feb 13, 2026 | 11.92% (0.11915) | 93.58th | v4 (v2025.03.14) |
| Jun 8, 2025 | 15.26% (0.15258) | 94.25th | v4 (v2025.03.14) |
| Mar 30, 2025 | 17.22% (0.17225) | 94.49th | v4 (v2025.03.14) |
| Mar 29, 2025 | 20.34% (0.20337) | 92.72th | v4 (v2025.03.14) |
| Mar 17, 2025 | 17.22% (0.17225) | 94.52th | v4 (v2025.03.14) |
| Dec 12, 2024 | 2.72% (0.02722) | 90.89th | v3 (v2023.03.01) |
| Dec 3, 2024 | 2.72% (0.02722) | 90.85th | v3 (v2023.03.01) |
| Jul 4, 2024 | 1.49% (0.01489) | 86.93th | v3 (v2023.03.01) |
| Mar 11, 2024 | 1.62% (0.01624) | 87.17th | v3 (v2023.03.01) |
| Dec 28, 2023 | 1.77% (0.01775) | 86.66th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.56% (0.01561) | 85.14th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.93% (0.03932) | 85.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.93% (0.03932) | 84.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.93% (0.03932) | 67.70th | v2 (v2022.01.01) |
No CWE recorded.
References (42)
- http://android-developers.blogspot.com/2008/03/android-sdk-update-m5-rc15-released.html x_refsource_CONFIRMThird Party Advisory
- http://bugs.gentoo.org/show_bug.cgi?id=195261 x_refsource_CONFIRMThird Party Advisory
- http://docs.info.apple.com/article.html?artnum=307562 x_refsource_CONFIRMThird Party Advisory
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.html vendor-advisoryx_refsource_APPLEMailing ListThird Party Advisory
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html vendor-advisoryx_refsource_APPLEMailing ListThird Party Advisory
- http://secunia.com/advisories/27093 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/27284 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/27405 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/27529 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/27629 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/27746 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/29420 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/30161 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/30430 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35302 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35386 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.520323 vendor-advisoryx_refsource_SLACKWAREThird Party Advisory
- http://sourceforge.net/mailarchive/forum.php?thread_name=3.0.6.32.20071004082318.012a7628%40mail.comcast.net&forum_name=png-mng-implement mailing-listx_refsource_MLISTPatchThird Party Advisory
- http://sourceforge.net/mailarchive/message.php?msg_name=5122753600C3E94F87FBDFFCC090D1FF0400EBC5%40MERCMBX07.na.sas.com mailing-listx_refsource_MLISTThird Party Advisory
- http://sourceforge.net/mailarchive/message.php?msg_name=e56ccc8f0709140846k24e9a040r81623783b6b1c00f%40mail.gmail.com mailing-listx_refsource_MLISTPatchThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-259989-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020521.1-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://support.avaya.com/elmodocs2/security/ASA-2009-208.htm x_refsource_CONFIRMThird Party Advisory
- http://www.coresecurity.com/?action=item&id=2148 x_refsource_MISCThird Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200711-08.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:217 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.securityfocus.com/archive/1/483582/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/489135/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/25956 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/usn-538-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA08-150A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2007/3390 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2008/0924/references vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2008/1697 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2009/1462 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2009/1560 vdb-entryx_refsource_VUPENThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2007-5268 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=324751 Issue Tracking
- https://issues.rpath.com/browse/RPL-1814 x_refsource_CONFIRMBroken Link
- https://nvd.nist.gov/vuln/detail/CVE-2007-5268
- https://www.cve.org/CVERecord?id=CVE-2007-5268
Change history (0)
No recorded changes yet.