CVE-2008-3964

Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the png_push_read_zTXt function in pngread.c, and possibly related to (2) pngtest.c.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
VendorProductVersion
libpnglibpng
𝑥
< 1.2.32
libpnglibpng
1.4.0:beta1
libpnglibpng
1.4.0:beta10
libpnglibpng
1.4.0:beta11
libpnglibpng
1.4.0:beta12
libpnglibpng
1.4.0:beta13
libpnglibpng
1.4.0:beta14
libpnglibpng
1.4.0:beta15
libpnglibpng
1.4.0:beta16
libpnglibpng
1.4.0:beta17
libpnglibpng
1.4.0:beta18
libpnglibpng
1.4.0:beta19
libpnglibpng
1.4.0:beta2
libpnglibpng
1.4.0:beta20
libpnglibpng
1.4.0:beta21
libpnglibpng
1.4.0:beta22
libpnglibpng
1.4.0:beta23
libpnglibpng
1.4.0:beta24
libpnglibpng
1.4.0:beta25
libpnglibpng
1.4.0:beta26
libpnglibpng
1.4.0:beta27
libpnglibpng
1.4.0:beta28
libpnglibpng
1.4.0:beta29
libpnglibpng
1.4.0:beta3
libpnglibpng
1.4.0:beta30
libpnglibpng
1.4.0:beta31
libpnglibpng
1.4.0:beta32
libpnglibpng
1.4.0:beta33
libpnglibpng
1.4.0:beta4
libpnglibpng
1.4.0:beta5
libpnglibpng
1.4.0:beta6
libpnglibpng
1.4.0:beta7
libpnglibpng
1.4.0:beta8
libpnglibpng
1.4.0:beta9
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libpng
intrepid
Fixed 1.2.27-1ubuntu0.1
released
hardy
Fixed 1.2.15~beta5-3ubuntu0.1
released
gutsy
Fixed 1.2.15~beta5-2ubuntu0.2
released
feisty
ignored
dapper
Fixed 1.2.8rel-5ubuntu0.4
released
References