// For flags

CVE-2008-3964

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the png_push_read_zTXt function in pngread.c, and possibly related to (2) pngtest.c.

Múltiples desbordamientos de entero en libpng versiones anteriores a 1.2.32beta01, y 1.4 versiones anteriores a 1.4.0beta34, permiten a atacantes dependientes de contexto provocar una denegación de servicio (caída) o tener otros impactos desconocidos a través de una imagen PNG con fragmentos zTXt manipulados, relacionado con (1) la función png_push_read_zTXt en pngread.c, y posiblemente relacionado con (2) pngtest.c.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-09-09 CVE Reserved
  • 2008-09-10 CVE Published
  • 2024-07-07 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-193: Off-by-one Error
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
< 1.2.32
Search vendor "Libpng" for product "Libpng" and version " < 1.2.32"
-
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta1
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta10
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta11
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta12
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta13
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta14
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta15
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta16
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta17
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta18
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta19
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta2
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta20
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta21
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta22
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta23
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta24
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta25
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta26
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta27
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta28
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta29
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta3
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta30
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta31
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta32
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta33
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta4
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta5
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta6
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta7
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta8
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.4.0
Search vendor "Libpng" for product "Libpng" and version "1.4.0"
beta9
Affected