5
CVSSv2

CVE-2002-0728

Published: 12/08/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Buffer overflow in the progressive reader for libpng 1.2.x prior to 1.2.4, and 1.0.x prior to 1.0.14, allows malicious users to cause a denial of service (crash) via a PNG data stream that has more IDAT data than indicated by the IHDR chunk.

Vulnerable Product Search on Vulmon Subscribe to Product

greg roelofs libpng 1.2.4

greg roelofs libpng 1.0.14

Vendor Advisories

Developers of the PNG library have fixed a buffer overflow in the progressive reader when the PNG datastream contains more IDAT data than indicated by the IHDR chunk Such deliberately malformed datastreams would crash applications which could potentially allow an attacker to execute malicious code Programs such as Galeon, Konqueror and various ot ...