Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-4214

Опубликовано: 25 июн. 2019
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.

Отчет

Red Hat Enterprise Linux 5,6,7,8, & 9 are not affected because the pngimage.c program is not shipped with our binary RPMs.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libpngNot affected
Red Hat Enterprise Linux 6libpngNot affected
Red Hat Enterprise Linux 7libpngNot affected
Red Hat Enterprise Linux 8libpngNot affected
Red Hat Enterprise Linux 9libpngNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2043393libpng: hardcoded value leads to heap-overflow

EPSS

Процентиль: 45%
0.00223
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.

CVSS3: 5.5
nvd
больше 3 лет назад

A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.

CVSS3: 5.5
debian
больше 3 лет назад

A heap overflow flaw was found in libpngs' pngimage.c program. This fl ...

CVSS3: 5.5
github
больше 3 лет назад

A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.

CVSS3: 5.5
fstec
больше 3 лет назад

Уязвимость компонента pngimage.c библиотеки libpng, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 45%
0.00223
Низкий

5.5 Medium

CVSS3