Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-2042

Опубликовано: 04 июн. 2009
Источник: redhat
CVSS2: 2.6

Описание

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libpngAffected
Red Hat Enterprise Linux 3libpngFixedRHSA-2010:053414.07.2010
Red Hat Enterprise Linux 3libpng10FixedRHSA-2010:053414.07.2010
Red Hat Enterprise Linux 4libpngFixedRHSA-2010:053414.07.2010
Red Hat Enterprise Linux 4libpng10FixedRHSA-2010:053414.07.2010
Red Hat Enterprise Linux 5libpngFixedRHSA-2010:053414.07.2010

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=504782libpng: Interlaced Images Information Disclosure Vulnerability

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
больше 16 лет назад

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

nvd
больше 16 лет назад

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

debian
больше 16 лет назад

libpng before 1.2.37 does not properly parse 1-bit interlaced images w ...

github
больше 3 лет назад

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

fstec
больше 16 лет назад

Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации

2.6 Low

CVSS2