4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
9.2 High
AI Score
Confidence
High
0.007 Low
EPSS
Percentile
80.9%
libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via “out-of-bounds pixels” in the file.
archives.neohapsis.com/archives/bugtraq/2010-04/0077.html
archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html
lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
lists.vmware.com/pipermail/security-announce/2010/000090.html
secunia.com/advisories/35346
secunia.com/advisories/35470
secunia.com/advisories/35524
secunia.com/advisories/35594
secunia.com/advisories/39206
secunia.com/advisories/39215
secunia.com/advisories/39251
security.gentoo.org/glsa/glsa-200906-01.xml
slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.551809
support.apple.com/kb/HT4077
ubuntu.com/usn/usn-913-1
www.debian.org/security/2010/dsa-2032
www.libpng.org/pub/png/libpng.html
www.mandriva.com/security/advisories?name=MDVSA-2010:063
www.securityfocus.com/bid/35233
www.vmware.com/security/advisories/VMSA-2010-0007.html
www.vupen.com/english/advisories/2009/1510
www.vupen.com/english/advisories/2010/0637
www.vupen.com/english/advisories/2010/0682
www.vupen.com/english/advisories/2010/0847
exchange.xforce.ibmcloud.com/vulnerabilities/50966
www.redhat.com/archives/fedora-package-announce/2009-June/msg00218.html
www.redhat.com/archives/fedora-package-announce/2009-June/msg00630.html