Lucene search

K
cve[email protected]CVE-2011-3045
HistoryMar 22, 2012 - 4:55 p.m.

CVE-2011-3045

2012-03-2216:55:01
CWE-190
web.nvd.nist.gov
138
4
cve-2011-3045
libpng
integer signedness error
pngrutil.c
remote attackers
denial of service
arbitrary code
png file

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

9 High

AI Score

Confidence

High

0.832 High

EPSS

Percentile

98.5%

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.

Affected configurations

NVD
Node
googlechromeRange<17.0.963.83
Node
redhatgluster_storageMatch2.0
OR
redhatstorageMatch2.0
OR
redhatstorage_for_public_cloudMatch2.0
OR
debiandebian_linuxMatch6.0
OR
fedoraprojectfedoraMatch15
OR
fedoraprojectfedoraMatch16
OR
fedoraprojectfedoraMatch17
OR
opensuseopensuseMatch12.1
OR
redhatenterprise_linuxMatch5.0
OR
redhatenterprise_linuxMatch6.0
OR
redhatenterprise_linux_desktopMatch5.0
OR
redhatenterprise_linux_desktopMatch6.0
OR
redhatenterprise_linux_server_ausMatch6.2
OR
redhatenterprise_linux_server_eusMatch6.2
OR
redhatenterprise_linux_workstationMatch5.0
OR
redhatenterprise_linux_workstationMatch6.0
Node
libpnglibpngRange<1.5.10

References

Social References

More

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

9 High

AI Score

Confidence

High

0.832 High

EPSS

Percentile

98.5%