7.5
CVSSv2

CVE-2002-0660

Published: 12/08/2002 Updated: 08/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow malicious users to cause a denial of service and possibly execute arbitrary code, a different vulnerability than CVE-2002-0728.

Vulnerable Product Search on Vulmon Subscribe to Product

greg roelofs libpng3 1.2.1

greg roelofs libpng 1.0.12

Vendor Advisories

Developers of the PNG library have fixed a buffer overflow in the progressive reader when the PNG datastream contains more IDAT data than indicated by the IHDR chunk Such deliberately malformed datastreams would crash applications which could potentially allow an attacker to execute malicious code Programs such as Galeon, Konqueror and various ot ...