3.3
CVSSv3

CVE-2020-27818

Published: 08/12/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libpng pngcheck 2.4.0

fedoraproject fedora 31

fedoraproject fedora 32

fedoraproject fedora 33

fedoraproject fedora 34

fedoraproject extra packages for enterprise linux 8.0

fedoraproject extra packages for enterprise linux 7.0

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #976350 pngcheck: CVE-2020-27818 Package: src:pngcheck; Maintainer for src:pngcheck is David da Silva Polverari <davidpolverari@gmailcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 3 Dec 2020 20:06:01 UTC Severity: important Tags: security, upstream Found in version ...