// For flags

CVE-2007-5268

Gentoo Linux Security Advisory 201412-11

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG image.

pngrtran.c en libpng anterior a 1.0.29 y 1.2.x anterior a 1.2.21 utiliza (1) operaciones lógicas en vez de operación sobre bits y (2) comparaciones incorrectas, lo cual podría permitir a atacantes remotos provocar una denegación de servicio (caída) mediante una imagen PNG manipulada artesanalmente.

An off-by-one error when handling ICC profile chunks in the png_set_iCCP() function was discovered. George Cook and Jeff Phillips reported several errors in pngrtran.c, the use of logical instead of a bitwise functions and incorrect comparisons. Tavis Ormandy reported out-of-bounds read errors in several PNG chunk handling functions. Versions less than 1.2.21-r3 are affected.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-10-08 CVE Reserved
  • 2007-10-08 CVE Published
  • 2008-03-04 First Exploit
  • 2024-08-07 CVE Updated
  • 2025-06-08 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
References (39)
URL Tag Source
http://android-developers.blogspot.com/2008/03/android-sdk-update-m5-rc15-released.html Third Party Advisory
http://bugs.gentoo.org/show_bug.cgi?id=195261 Third Party Advisory
http://docs.info.apple.com/article.html?artnum=307562 Third Party Advisory
http://secunia.com/advisories/27093 Third Party Advisory
http://secunia.com/advisories/27284 Third Party Advisory
http://secunia.com/advisories/27405 Third Party Advisory
http://secunia.com/advisories/27529 Third Party Advisory
http://secunia.com/advisories/27629 Third Party Advisory
http://secunia.com/advisories/27746 Third Party Advisory
http://secunia.com/advisories/29420 Third Party Advisory
http://secunia.com/advisories/30161 Third Party Advisory
http://secunia.com/advisories/30430 Third Party Advisory
http://secunia.com/advisories/35302 Third Party Advisory
http://secunia.com/advisories/35386 Third Party Advisory
http://sourceforge.net/mailarchive/message.php?msg_name=5122753600C3E94F87FBDFFCC090D1FF0400EBC5%40MERCMBX07.na.sas.com Mailing List
http://support.avaya.com/elmodocs2/security/ASA-2009-208.htm Third Party Advisory
http://www.coresecurity.com/?action=item&id=2148 Third Party Advisory
http://www.securityfocus.com/archive/1/483582/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/489135/100/0/threaded Mailing List
http://www.securityfocus.com/bid/25956 Third Party Advisory
http://www.us-cert.gov/cas/techalerts/TA08-150A.html Third Party Advisory
http://www.vupen.com/english/advisories/2007/3390 Third Party Advisory
http://www.vupen.com/english/advisories/2008/0924/references Third Party Advisory
http://www.vupen.com/english/advisories/2008/1697 Third Party Advisory
http://www.vupen.com/english/advisories/2009/1462 Third Party Advisory
http://www.vupen.com/english/advisories/2009/1560 Third Party Advisory
https://issues.rpath.com/browse/RPL-1814 Broken Link
URL Date SRC
https://packetstorm.news/files/id/64260 2008-03-04
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
< 1.0.29
Search vendor "Libpng" for product "Libpng" and version " < 1.0.29"
-
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
>= 1.2.0 < 1.2.21
Search vendor "Libpng" for product "Libpng" and version " >= 1.2.0 < 1.2.21"
-
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
6.06
Search vendor "Canonical" for product "Ubuntu Linux" and version "6.06"
lts
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
6.10
Search vendor "Canonical" for product "Ubuntu Linux" and version "6.10"
-
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
7.04
Search vendor "Canonical" for product "Ubuntu Linux" and version "7.04"
-
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
7.10
Search vendor "Canonical" for product "Ubuntu Linux" and version "7.10"
-
Affected