Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-2042

Опубликовано: 04 июн. 2009
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libpngAffected
Red Hat Enterprise Linux 3libpngFixedRHSA-2010:053414.07.2010
Red Hat Enterprise Linux 3libpng10FixedRHSA-2010:053414.07.2010
Red Hat Enterprise Linux 4libpngFixedRHSA-2010:053414.07.2010
Red Hat Enterprise Linux 4libpng10FixedRHSA-2010:053414.07.2010
Red Hat Enterprise Linux 5libpngFixedRHSA-2010:053414.07.2010

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=504782libpng: Interlaced Images Information Disclosure Vulnerability

EPSS

Процентиль: 85%
0.02748
Низкий

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
около 16 лет назад

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

nvd
около 16 лет назад

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

debian
около 16 лет назад

libpng before 1.2.37 does not properly parse 1-bit interlaced images w ...

github
около 3 лет назад

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

fstec
почти 16 лет назад

Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации

EPSS

Процентиль: 85%
0.02748
Низкий

2.6 Low

CVSS2