CVE Vulnerabilities

CVE-2005-2978

Published: Oct 18, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

pnmtopng in netpbm before 10.25, when using the -trans option, uses uninitialized size and index variables when converting Portable Anymap (PNM) images to Portable Network Graphics (PNG), which might allow attackers to execute arbitrary code by modifying the stack.

Affected Software

NameVendorStart VersionEnd Version
NetpbmNetpbm10.0 (including)10.0 (including)
NetpbmNetpbm10.1 (including)10.1 (including)
NetpbmNetpbm10.2 (including)10.2 (including)
NetpbmNetpbm10.3 (including)10.3 (including)
NetpbmNetpbm10.4 (including)10.4 (including)
NetpbmNetpbm10.5 (including)10.5 (including)
NetpbmNetpbm10.6 (including)10.6 (including)
NetpbmNetpbm10.7 (including)10.7 (including)
NetpbmNetpbm10.8 (including)10.8 (including)
NetpbmNetpbm10.9 (including)10.9 (including)
NetpbmNetpbm10.10 (including)10.10 (including)
NetpbmNetpbm10.11 (including)10.11 (including)
NetpbmNetpbm10.12 (including)10.12 (including)
NetpbmNetpbm10.13 (including)10.13 (including)
NetpbmNetpbm10.14 (including)10.14 (including)
NetpbmNetpbm10.15 (including)10.15 (including)
NetpbmNetpbm10.16 (including)10.16 (including)
NetpbmNetpbm10.17 (including)10.17 (including)
NetpbmNetpbm10.18 (including)10.18 (including)
NetpbmNetpbm10.19 (including)10.19 (including)
NetpbmNetpbm10.20 (including)10.20 (including)
NetpbmNetpbm10.21 (including)10.21 (including)
NetpbmNetpbm10.22 (including)10.22 (including)
NetpbmNetpbm10.23 (including)10.23 (including)
NetpbmNetpbm10.24 (including)10.24 (including)
Red Hat Enterprise Linux 4RedHatnetpbm-0:10.25-2.EL4.2*
Netpbm-freeUbuntudapper*
Netpbm-freeUbuntudevel*
Netpbm-freeUbuntuedgy*
Netpbm-freeUbuntufeisty*
Netpbm-freeUbuntuupstream*

References