Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-1670
HistoryApr 28, 2008 - 12:00 a.m.

CVE-2008-1670

2008-04-2800:00:00
ubuntu.com
ubuntu.com
8

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.039 Low

EPSS

Percentile

92.0%

Heap-based buffer overflow in the progressive PNG Image loader
(decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote
attackers to cause a denial of service (crash) and possibly execute
arbitrary code via a crafted image.

Bugs

Notes

Author Note
mdeslaur reproducer in RH bug

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.039 Low

EPSS

Percentile

92.0%