7.5
CVSSv2

CVE-2005-2978

Published: 18/10/2005 Updated: 03/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

pnmtopng in netpbm prior to 10.25, when using the -trans option, uses uninitialized size and index variables when converting Portable Anymap (PNM) images to Portable Network Graphics (PNG), which might allow malicious users to execute arbitrary code by modifying the stack.

Vulnerable Product Search on Vulmon Subscribe to Product

netpbm netpbm 10.0

netpbm netpbm 10.1

netpbm netpbm 10.17

netpbm netpbm 10.18

netpbm netpbm 10.24

netpbm netpbm 10.3

netpbm netpbm 10.15

netpbm netpbm 10.16

netpbm netpbm 10.22

netpbm netpbm 10.23

netpbm netpbm 10.8

netpbm netpbm 10.9

netpbm netpbm 10.10

netpbm netpbm 10.11

netpbm netpbm 10.19

netpbm netpbm 10.2

netpbm netpbm 10.4

netpbm netpbm 10.5

netpbm netpbm 10.12

netpbm netpbm 10.13

netpbm netpbm 10.14

netpbm netpbm 10.20

netpbm netpbm 10.21

netpbm netpbm 10.6

netpbm netpbm 10.7

Vendor Advisories

Synopsis netpbm security update Type/Severity Security Advisory: Moderate Topic Updated netpbm packages that fix a security issue are now availableThis update has been rated as having moderate security impact by the Red HatSecurity Response Team Description The netpbm package contains a l ...
A buffer overflow was found in the “pnmtopng” conversion program By tricking an user (or automated system) to process a specially crafted PNM image with pnmtopng, this could be exploited to execute arbitrary code with the privileges of the user running pnmtopng ...