CVE Vulnerabilities

CVE-2020-35511

Buffer Over-read

Published: Aug 23, 2022 | Modified: Feb 02, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A global buffer overflow was discovered in pngcheck function in pngcheck-2.4.0(5 patches applied) via a crafted png file.

Weakness

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Affected Software

Name Vendor Start Version End Version
Pngcheck Libpng 2.4.0 (including) 2.4.0 (including)
Pngcheck Ubuntu bionic *
Pngcheck Ubuntu devel *
Pngcheck Ubuntu esm-apps/bionic *
Pngcheck Ubuntu esm-apps/noble *
Pngcheck Ubuntu esm-apps/xenial *
Pngcheck Ubuntu focal *
Pngcheck Ubuntu mantic *
Pngcheck Ubuntu noble *
Pngcheck Ubuntu oracular *
Pngcheck Ubuntu trusty *
Pngcheck Ubuntu xenial *

References