CVE-2010-2249

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
VendorProductVersion
libpnglibpng
𝑥
< 1.2.44
libpnglibpng
1.4.0 ≤
𝑥
< 1.4.3
appleitunes
𝑥
< 10.2
applesafari
𝑥
< 5.0.4
appleiphone_os
2.0 ≤
𝑥
≤ 4.1
appletvos
𝑥
< 4.1.0
opensuseopensuse
11.1
opensuseopensuse
11.2
vmwareplayer
2.5 ≤
𝑥
< 2.5.5
vmwareplayer
3.1 ≤
𝑥
< 3.1.2
vmwareworkstation
6.5.0 ≤
𝑥
< 6.5.5
vmwareworkstation
7.1 ≤
𝑥
< 7.1.2
canonicalubuntu_linux
6.06
canonicalubuntu_linux
8.04
canonicalubuntu_linux
9.04
canonicalubuntu_linux
9.10
canonicalubuntu_linux
10.04
debiandebian_linux
5.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tuxonice-userui
bookworm/contrib
1.1+dfsg1.gc3bdd83-4
fixed
bullseye/contrib
1.1+dfsg1.gc3bdd83-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
maverick
ignored
lucid
ignored
karmic
dne
jaunty
dne
hardy
dne
dapper
dne
firefox
maverick
ignored
lucid
ignored
karmic
dne
jaunty
dne
hardy
ignored
dapper
ignored
libpng
maverick
not-affected
lucid
Fixed 1.2.42-1ubuntu2.1
released
karmic
Fixed 1.2.37-1ubuntu0.2
released
jaunty
Fixed 1.2.27-2ubuntu2.2
released
hardy
Fixed 1.2.15~beta5-3ubuntu0.3
released
dapper
Fixed 1.2.8rel-5ubuntu0.6
released
References