7.5
CVSSv2

CVE-2002-1363

Published: 26/12/2002 Updated: 10/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Portable Network Graphics (PNG) library libpng 1.2.5 and previous versions does not correctly calculate offsets, which allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers.

Vulnerable Product Search on Vulmon Subscribe to Product

greg roelofs libpng 1.0.13

greg roelofs libpng 1.0.14

greg roelofs libpng 1.2.1

greg roelofs libpng 1.2.2

greg roelofs libpng 1.2.3

greg roelofs libpng 1.0.7

greg roelofs libpng 1.0.8

greg roelofs libpng 1.0.5

greg roelofs libpng 1.0.6

greg roelofs libpng 1.2.4

greg roelofs libpng 1.0.11

greg roelofs libpng 1.0.12

greg roelofs libpng 1.0.9

greg roelofs libpng 1.2.0

Vendor Advisories

Synopsis libpng security update Type/Severity Security Advisory: Critical Topic Updated libpng packages that fix several issues are now available Description The libpng package contains a library of functions for creating andmanipulating PNG (Portable Network Graphics) image format filesD ...
Synopsis libpng security update Type/Severity Security Advisory: Important Topic Updated libpng packages that fix a possible buffer overflow are now available Description The libpng package contains a library of functions for creating andmanipulating PNG (Portable Network Graphics) image f ...
Glenn Randers-Pehrson discovered a problem in connection with 16-bit samples from libpng, an interface for reading and writing PNG (Portable Network Graphics) format files The starting offsets for the loops are calculated incorrectly which causes a buffer overrun beyond the beginning of the row buffer For the current stable distribution (woody) t ...