Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w4pv-vqp3-f753

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.

Ссылки

EPSS

Процентиль: 89%
0.04701
Низкий

8.8 High

CVSS3

Дефекты

CWE-190
CWE-195

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 13 лет назад

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.

redhat
больше 13 лет назад

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.

CVSS3: 8.8
nvd
около 13 лет назад

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.

CVSS3: 8.8
msrc
8 дней назад

Описание отсутствует

CVSS3: 8.8
debian
около 13 лет назад

Integer signedness error in the png_inflate function in pngrutil.c in ...

EPSS

Процентиль: 89%
0.04701
Низкий

8.8 High

CVSS3

Дефекты

CWE-190
CWE-195