CVE-2008-3964
11.09.2008, 01:13
Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the png_push_read_zTXt function in pngread.c, and possibly related to (2) pngtest.c.Enginsight
Vendor | Product | Version |
---|---|---|
libpng | libpng | 𝑥 < 1.2.32 |
libpng | libpng | 1.4.0:beta1 |
libpng | libpng | 1.4.0:beta10 |
libpng | libpng | 1.4.0:beta11 |
libpng | libpng | 1.4.0:beta12 |
libpng | libpng | 1.4.0:beta13 |
libpng | libpng | 1.4.0:beta14 |
libpng | libpng | 1.4.0:beta15 |
libpng | libpng | 1.4.0:beta16 |
libpng | libpng | 1.4.0:beta17 |
libpng | libpng | 1.4.0:beta18 |
libpng | libpng | 1.4.0:beta19 |
libpng | libpng | 1.4.0:beta2 |
libpng | libpng | 1.4.0:beta20 |
libpng | libpng | 1.4.0:beta21 |
libpng | libpng | 1.4.0:beta22 |
libpng | libpng | 1.4.0:beta23 |
libpng | libpng | 1.4.0:beta24 |
libpng | libpng | 1.4.0:beta25 |
libpng | libpng | 1.4.0:beta26 |
libpng | libpng | 1.4.0:beta27 |
libpng | libpng | 1.4.0:beta28 |
libpng | libpng | 1.4.0:beta29 |
libpng | libpng | 1.4.0:beta3 |
libpng | libpng | 1.4.0:beta30 |
libpng | libpng | 1.4.0:beta31 |
libpng | libpng | 1.4.0:beta32 |
libpng | libpng | 1.4.0:beta33 |
libpng | libpng | 1.4.0:beta4 |
libpng | libpng | 1.4.0:beta5 |
libpng | libpng | 1.4.0:beta6 |
libpng | libpng | 1.4.0:beta7 |
libpng | libpng | 1.4.0:beta8 |
libpng | libpng | 1.4.0:beta9 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References