libpng: buffer overflow in png_inflate caused by invalid type conversions
Published Mar 22, 2012
8.8
HIGHCVSS 3.1
EPSS 3.56%
Description
Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.
Affected products
No data.
Configuration 2
- 2.0
- 2.0
- 2.0
- 6.0
- 15
- 16
- 17
- 12.1
- 5.0
- 6.0
- 5.0
- 6.0
- 6.2
- 6.2
- 5.0
- 6.0
No data.
Red Hat Enterprise Linux 5
libpng-2:1.2.10-16.el5_8
Fixed · RHSA-2012:0407
Red Hat Enterprise Linux 6
libpng-2:1.2.48-1.el6_2
Fixed · RHSA-2012:0407
Red Hat Enterprise Linux 4
libpng
Will not fix
Red Hat Enterprise Linux 4
libpng10
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | libpng-2:1.2.10-16.el5_8 | Fixed | RHSA-2012:0407 |
| Red Hat Enterprise Linux 6 | libpng-2:1.2.48-1.el6_2 | Fixed | RHSA-2012:0407 |
| Red Hat Enterprise Linux 4 | libpng | Will not fix | n/a |
| Red Hat Enterprise Linux 4 | libpng10 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jun 9, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (31 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.56% (0.03556) | 88.94th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.57% (0.03567) | 87.83th | v5 (v2026.06.15) |
| Jun 13, 2026 | 6.31% (0.06306) | 91.19th | v4 (v2025.03.14) |
| May 27, 2026 | 4.58% (0.04580) | 89.35th | v4 (v2025.03.14) |
| May 22, 2026 | 3.50% (0.03501) | 87.76th | v4 (v2025.03.14) |
| Jan 23, 2026 | 4.58% (0.04580) | 88.91th | v4 (v2025.03.14) |
| Jan 20, 2026 | 3.50% (0.03501) | 87.25th | v4 (v2025.03.14) |
| Jan 18, 2026 | 6.12% (0.06118) | 90.50th | v4 (v2025.03.14) |
| Oct 19, 2025 | 7.72% (0.07724) | 91.50th | v4 (v2025.03.14) |
| Jul 13, 2025 | 5.81% (0.05814) | 90.09th | v4 (v2025.03.14) |
| Jun 10, 2025 | 4.70% (0.04701) | 88.82th | v4 (v2025.03.14) |
| May 21, 2025 | 7.36% (0.07357) | 91.21th | v4 (v2025.03.14) |
| May 18, 2025 | 4.34% (0.04338) | 88.32th | v4 (v2025.03.14) |
| Mar 30, 2025 | 8.05% (0.08048) | 91.31th | v4 (v2025.03.14) |
| Mar 29, 2025 | 12.13% (0.12126) | 89.66th | v4 (v2025.03.14) |
| Mar 19, 2025 | 8.05% (0.08048) | 91.06th | v4 (v2025.03.14) |
| Mar 17, 2025 | 6.17% (0.06165) | 90.13th | v4 (v2025.03.14) |
| Dec 30, 2024 | 26.15% (0.26153) | 96.73th | v3 (v2023.03.01) |
| Dec 17, 2024 | 22.62% (0.22623) | 96.52th | v3 (v2023.03.01) |
| Sep 20, 2024 | 18.54% (0.18539) | 96.30th | v3 (v2023.03.01) |
| Jul 29, 2024 | 16.85% (0.16851) | 96.12th | v3 (v2023.03.01) |
| Apr 10, 2024 | 14.17% (0.14175) | 95.60th | v3 (v2023.03.01) |
| Feb 16, 2024 | 15.81% (0.15812) | 95.75th | v3 (v2023.03.01) |
| Oct 21, 2023 | 20.86% (0.20862) | 95.83th | v3 (v2023.03.01) |
| Aug 18, 2023 | 21.48% (0.21476) | 95.83th | v3 (v2023.03.01) |
| Jun 16, 2023 | 22.20% (0.22202) | 95.81th | v3 (v2023.03.01) |
| Apr 16, 2023 | 24.88% (0.24880) | 95.94th | v3 (v2023.03.01) |
| Mar 7, 2023 | 21.54% (0.21544) | 95.65th | v3 (v2023.03.01) |
| Mar 6, 2023 | 6.60% (0.06604) | 91.53th | v2 (v2022.01.01) |
| Apr 1, 2022 | 6.60% (0.06604) | 90.72th | v2 (v2022.01.01) |
| Feb 4, 2022 | 6.60% (0.06604) | 78.62th | v2 (v2022.01.01) |
References (28)
- http://code.google.com/p/chromium/issues/detail?id=116162 x_refsource_CONFIRMVendor Advisory
- http://googlechromereleases.blogspot.com/2012/03/stable-channel-update_21.html x_refsource_CONFIRMRelease NotesVendor Advisory
- http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=commit%3Bh=a8c319a2b281af68f7ca0e2f9a28ca57b44ceb2b x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2012-March/075424.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-March/075619.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-March/075981.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-March/075987.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-March/076461.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-March/076731.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00000.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2012-03/msg00051.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0407.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0488.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://secunia.com/advisories/48320 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/48485 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/48512 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/48554 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/49660 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://security.gentoo.org/glsa/glsa-201206-15.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://src.chromium.org/viewvc/chrome?view=rev&revision=125311 x_refsource_CONFIRMPatchVendor Advisory
- http://www.debian.org/security/2012/dsa-2439 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:033 vendor-advisoryx_refsource_MANDRIVANot Applicable
- http://www.securitytracker.com/id?1026823 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2011-3045 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=799000 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-3045
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14763 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2011-3045
Change history (0)
No recorded changes yet.