CVE-2008-3964
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the png_push_read_zTXt function in pngread.c, and possibly related to (2) pngtest.c.
Múltiples desbordamientos de entero en libpng versiones anteriores a 1.2.32beta01, y 1.4 versiones anteriores a 1.4.0beta34, permiten a atacantes dependientes de contexto provocar una denegación de servicio (caída) o tener otros impactos desconocidos a través de una imagen PNG con fragmentos zTXt manipulados, relacionado con (1) la función png_push_read_zTXt en pngread.c, y posiblemente relacionado con (2) pngtest.c.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-09-09 CVE Reserved
- 2008-09-10 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-193: Off-by-one Error
CAPEC
References (18)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/31781 | Third Party Advisory | |
http://secunia.com/advisories/33137 | Third Party Advisory | |
http://secunia.com/advisories/35302 | Third Party Advisory | |
http://secunia.com/advisories/35386 | Third Party Advisory | |
http://sourceforge.net/mailarchive/forum.php?thread_name=e56ccc8f0809180317u6a5306fg14683947affb3e1b%40mail.gmail.com&forum_name=png-mng-implement | Mailing List | |
http://sourceforge.net/project/shownotes.php?group_id=5624&release_id=624517 | Product | |
http://support.avaya.com/elmodocs2/security/ASA-2009-208.htm | Third Party Advisory | |
http://www.kb.cert.org/vuls/id/889484 | Third Party Advisory |
|
http://www.openwall.com/lists/oss-security/2008/09/09/3 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2008/09/09/8 | Mailing List |
|
http://www.securityfocus.com/bid/31049 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44928 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
http://sourceforge.net/tracker/index.php?func=detail&aid=2095669&group_id=5624&atid=105624 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://sourceforge.net/project/shownotes.php?release_id=624518 | 2022-01-31 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | < 1.2.32 Search vendor "Libpng" for product "Libpng" and version " < 1.2.32" | - |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta1 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta10 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta11 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta12 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta13 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta14 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta15 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta16 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta17 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta18 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta19 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta2 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta20 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta21 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta22 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta23 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta24 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta25 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta26 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta27 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta28 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta29 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta3 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta30 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta31 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta32 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta33 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta4 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta5 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta6 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta7 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta8 |
Affected
| ||||||
Libpng Search vendor "Libpng" | Libpng Search vendor "Libpng" for product "Libpng" | 1.4.0 Search vendor "Libpng" for product "Libpng" and version "1.4.0" | beta9 |
Affected
|