Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-1205

Опубликовано: 25 июн. 2010
Источник: redhat
CVSS2: 6.8

Описание

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libpngNot affected
Red Hat Enterprise Linux 3libpngFixedRHSA-2010:053414.07.2010
Red Hat Enterprise Linux 3libpng10FixedRHSA-2010:053414.07.2010
Red Hat Enterprise Linux 3seamonkeyFixedRHSA-2010:054621.07.2010
Red Hat Enterprise Linux 4libpngFixedRHSA-2010:053414.07.2010
Red Hat Enterprise Linux 4libpng10FixedRHSA-2010:053414.07.2010
Red Hat Enterprise Linux 4seamonkeyFixedRHSA-2010:054621.07.2010
Red Hat Enterprise Linux 4firefoxFixedRHSA-2010:054721.07.2010
Red Hat Enterprise Linux 5libpngFixedRHSA-2010:053414.07.2010
Red Hat Enterprise Linux 5thunderbirdFixedRHSA-2010:054521.07.2010

Показывать по

Дополнительная информация

Статус:

Critical
https://bugzilla.redhat.com/show_bug.cgi?id=608238libpng: out-of-bounds memory write

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 15 лет назад

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

CVSS3: 9.8
nvd
почти 15 лет назад

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

CVSS3: 9.8
debian
почти 15 лет назад

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before ...

CVSS3: 9.8
github
около 3 лет назад

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

fstec
больше 14 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации

6.8 Medium

CVSS2