Vulnerability Name: | CVE-2007-5268 (CCN-37018) | ||||||||||||
Assigned: | 2007-10-04 | ||||||||||||
Published: | 2007-10-04 | ||||||||||||
Updated: | 2018-10-26 | ||||||||||||
Summary: | pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG image. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: CONFIRM Type: Third Party Advisory http://android-developers.blogspot.com/2008/03/android-sdk-update-m5-rc15-released.html Source: CONFIRM Type: Third Party Advisory http://bugs.gentoo.org/show_bug.cgi?id=195261 Source: MITRE Type: CNA CVE-2007-5268 Source: CONFIRM Type: Third Party Advisory http://docs.info.apple.com/article.html?artnum=307562 Source: APPLE Type: Mailing List, Third Party Advisory APPLE-SA-2008-05-28 Source: APPLE Type: Mailing List, Third Party Advisory APPLE-SA-2008-03-18 Source: CCN Type: SA27093 libpng Multiple Denial of Service Vulnerabilities Source: SECUNIA Type: Third Party Advisory 27093 Source: SECUNIA Type: Third Party Advisory 27284 Source: SECUNIA Type: Third Party Advisory 27405 Source: SECUNIA Type: Third Party Advisory 27529 Source: SECUNIA Type: Third Party Advisory 27629 Source: SECUNIA Type: Third Party Advisory 27746 Source: CCN Type: SA29420 Mac OS X Security Update Fixes Multiple Vulnerabilities Source: SECUNIA Type: Third Party Advisory 29420 Source: CCN Type: SA30161 Gentoo ltsp Multiple Vulnerabilities Source: SECUNIA Type: Third Party Advisory 30161 Source: CCN Type: SA30430 Apple Mac OS X Security Update Fixes Multiple Vulnerabilities Source: SECUNIA Type: Third Party Advisory 30430 Source: CCN Type: SA35302 Sun Solaris libpng Multiple Vulnerabilities Source: SECUNIA Type: Third Party Advisory 35302 Source: CCN Type: SA35386 Avaya CMS Solaris libpng Multiple Vulnerabilities Source: SECUNIA Type: Third Party Advisory 35386 Source: SLACKWARE Type: Third Party Advisory SSA:2007-325-01 Source: CCN Type: png-mng-implement Mailing List, 2007-10-04 12:23 Libpng-1.2.21 and libpng-1.0.29 released Source: MLIST Type: Patch, Third Party Advisory [png-mng-implement] 20071004 Libpng-1.2.21 and libpng-1.0.29 released Source: MLIST Type: Third Party Advisory [png-mng-implement] 20070911 FW: Compiler warnings for pngrtran.c Source: MLIST Type: Patch, Third Party Advisory [png-mng-implement] 20070914 libpng-1.0.29beta1 and libpng-1.2.21beta1 Source: CCN Type: SourceForge.net PNG reference library: libpng Source: CCN Type: Sun Alert ID: 259989 Security Vulnerability in Solaris libpng(3) May Allow Denial of Service (DoS) or Privilege Escalation Source: SUNALERT Type: Broken Link 259989 Source: SUNALERT Type: Broken Link 1020521 Source: CCN Type: Apple Web site About the security content of Security Update 2008-003 / Mac OS X 10.5.3 Source: CONFIRM Type: Third Party Advisory http://support.avaya.com/elmodocs2/security/ASA-2009-208.htm Source: CCN Type: ASA-2009-208 Security Vulnerability in Solaris libpng(3) May Allow Denial of Service (DoS) or Privilege Escalation (Sun 259989) Source: CCN Type: CORE-2008-0124 Multiple vulnerabilities in Google's Android SDK Source: MISC Type: Third Party Advisory http://www.coresecurity.com/?action=item&id=2148 Source: CCN Type: GLSA-200711-08 libpng: Multiple Denials of Service Source: GENTOO Type: Third Party Advisory GLSA-200711-08 Source: CCN Type: GLSA-200805-07 Linux Terminal Server Project: Multiple vulnerabilities Source: GENTOO Type: Third Party Advisory GLSA-200805-07 Source: MANDRIVA Type: Third Party Advisory MDKSA-2007:217 Source: CCN Type: OSVDB ID: 38273 libpng pngrtran.c Crafted PNG Multiple Method DoS Source: BUGTRAQ Type: Third Party Advisory, VDB Entry 20071112 FLEA-2007-0065-1 libpng Source: BUGTRAQ Type: Third Party Advisory, VDB Entry 20080304 CORE-2008-0124: Multiple vulnerabilities in Google's Android SDK Source: BID Type: Third Party Advisory, VDB Entry 25956 Source: CCN Type: BID-25956 Libpng Library Multiple Remote Denial of Service Vulnerabilities Source: CCN Type: USN-538-1 libpng vulnerabilities Source: UBUNTU Type: Third Party Advisory USN-538-1 Source: CCN Type: USN-730-1 libpng vulnerabilities Source: CERT Type: Third Party Advisory, US Government Resource TA08-150A Source: CCN Type: VMware Server Web site Key Features in VMware Server, What's New in Version 1.0.5 Source: CCN Type: Vmware Workstation Web site VMware Workstation 6.0 Release Notes, New in Version 6.0.3 Source: VUPEN Type: Third Party Advisory ADV-2007-3390 Source: VUPEN Type: Third Party Advisory ADV-2008-0924 Source: VUPEN Type: Third Party Advisory ADV-2008-1697 Source: VUPEN Type: Third Party Advisory ADV-2009-1462 Source: VUPEN Type: Third Party Advisory ADV-2009-1560 Source: XF Type: UNKNOWN libpng-logical-bitwise-dos(37018) Source: CONFIRM Type: Broken Link https://issues.rpath.com/browse/RPL-1814 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |