9.3
CVSSv2

CVE-2008-1670

Published: 28/04/2008 Updated: 08/08/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted image.

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde 4.0.0

kde kde 4.0.3

kde kde 4.0.1

kde kde 4.0.2

Vendor Advisories

Debian Bug report logs - #478283 kde4libs: CVE-2008-1670 heap based buffer overflow via specially encoded image Package: kde4libs; Maintainer for kde4libs is Debian/Kubuntu Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Reported by: Nico Golde <nion@debianorg> Date: Mon, 28 Apr 2008 15:18:01 UTC Severity: grav ...