7.1
CVSSv2

CVE-2008-6218

Published: 20/02/2009 Updated: 11/10/2018
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

Memory leak in the png_handle_tEXt function in pngrutil.c in libpng prior to 1.2.33 rc02 and 1.4.0 beta36 allows context-dependent malicious users to cause a denial of service (memory exhaustion) via a crafted PNG file.

Vulnerable Product Search on Vulmon Subscribe to Product

libpng libpng 1.2.1

libpng libpng 1.2.15

libpng libpng 1.2.19

libpng libpng 1.2.0

libpng libpng 1.2.10

libpng libpng 1.2.17

libpng libpng 1.2.11

libpng libpng 1.2.13

libpng libpng 1.2.23

libpng libpng 1.2.24

libpng libpng 1.2.21

libpng libpng 1.2.22

libpng libpng 1.2.20

libpng libpng 1.2.25

libpng libpng 1.2.3

libpng libpng 1.2.4

libpng libpng 1.2.28

libpng libpng 1.2.31

libpng libpng 1.2.2

libpng libpng 1.2.26

libpng libpng 1.2.9

libpng libpng 1.2.8

libpng libpng 1.2.6

libpng libpng 1.2.5

libpng libpng 1.2.18

libpng libpng 1.2.16

libpng libpng 1.2.14

libpng libpng 1.2.32

libpng libpng 1.2.27

libpng libpng 1.2.7

libpng libpng 1.2.30

libpng libpng 1.2.33

libpng libpng 1.4.0

libpng libpng 1.2.29

Vendor Advisories

Several vulnerabilities have been discovered in libpng, a library for reading and writing PNG files The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-2445 The png_handle_tRNS function allows attackers to cause a denial of service (application crash) via a grayscale PNG image with a bad tRNS chunk C ...