CVE Vulnerabilities

CVE-2004-0597

Published: Nov 23, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.

Affected Software

NameVendorStart VersionEnd Version
LibpngGreg_roelofs*1.2.5 (including)
Msn_messengerMicrosoft6.1 (including)6.1 (including)
Msn_messengerMicrosoft6.2 (including)6.2 (including)
Windows_media_playerMicrosoft9 (including)9 (including)
Windows_messengerMicrosoft5.0 (including)5.0 (including)
Red Hat Enterprise Linux 3RedHatlibpng-2:1.2.2-25*
Red Hat Enterprise Linux 3RedHatlibpng10-0:1.0.13-15*
Red Hat Enterprise Linux ES version 2.1RedHat*
Red Hat Enterprise Linux WS version 2.1RedHat*
LibpngUbuntudapper*
LibpngUbuntudevel*
LibpngUbuntuedgy*
LibpngUbuntufeisty*
Libpng3Ubuntudapper*
Libpng3Ubuntuedgy*

References