MEDIUM
libpng: off-by-one error in png_push_read_zTXt()
Published Sep 10, 2008
4.3
MEDIUMCVSS 2.0
EPSS 3.34%
Description
Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the png_push_read_zTXt function in pngread.c, and possibly related to (2) pngtest.c.
Affected products
No data.
OR
- < 1.2.32
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. These issues did not affect the versions of libpng as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Weaknesses (1)
References (25)
- http://secunia.com/advisories/31781 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/33137 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35302 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35386 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://security.gentoo.org/glsa/glsa-200812-15.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://sourceforge.net/mailarchive/forum.php?thread_name=e56ccc8f0809180317u6a5306fg14683947affb3e1b%40mail.gmail.com&forum_name=png-mng-implement mailing-listx_refsource_MLISTThird Party Advisory
- http://sourceforge.net/project/shownotes.php?group_id=5624&release_id=624517 x_refsource_CONFIRMProductThird Party Advisory
- http://sourceforge.net/project/shownotes.php?release_id=624518 x_refsource_CONFIRMBroken LinkPatch
- http://sourceforge.net/tracker/index.php?func=detail&aid=2095669&group_id=5624&atid=105624 x_refsource_CONFIRMExploitThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-259989-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020521.1-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://support.avaya.com/elmodocs2/security/ASA-2009-208.htm x_refsource_CONFIRMThird Party Advisory
- http://www.kb.cert.org/vuls/id/889484 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:051 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.openwall.com/lists/oss-security/2008/09/09/3 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2008/09/09/8 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/31049 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2008/2512 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2009/1462 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2009/1560 vdb-entryx_refsource_VUPENPermissions Required
- https://access.redhat.com/security/cve/CVE-2008-3964 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=461599 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44928 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2008-3964
- https://www.cve.org/CVERecord?id=CVE-2008-3964
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 10, 2008
Updated Aug 7, 2024
Reserved Sep 9, 2008
Link CVE-2008-3964
CISA Vulnrichment
Updated n/a