Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-3425

Опубликовано: 08 апр. 2012
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large avail_in field value in a PNG image.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libpngWill not fix
Red Hat Enterprise Linux 6libpngNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=813249libpng: Out-of heap-based buffer read by inflating certain PNG images

EPSS

Процентиль: 82%
0.01748
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large avail_in field value in a PNG image.

nvd
почти 13 лет назад

The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large avail_in field value in a PNG image.

msrc
2 месяца назад

Описание отсутствует

debian
почти 13 лет назад

The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1 ...

github
около 3 лет назад

The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large avail_in field value in a PNG image.

EPSS

Процентиль: 82%
0.01748
Низкий

4.3 Medium

CVSS2