10

CVE-2004-0597

Exploit

Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Greg RoelofsLibpng Version <= 1.2.5
MicrosoftMsn Messenger Version6.1
MicrosoftMsn Messenger Version6.2
MicrosoftWindows Messenger Version5.0
MicrosoftWindows Me Editionsecond_edition
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 85.09% 0.993
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
http://www.us-cert.gov/cas/techalerts/TA05-039A.html
Third Party Advisory
US Government Resource
http://www.kb.cert.org/vuls/id/388984
Third Party Advisory
US Government Resource
http://www.kb.cert.org/vuls/id/817368
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/10857
Patch
Vendor Advisory
Exploit
http://www.us-cert.gov/cas/techalerts/TA04-217A.html
Third Party Advisory
US Government Resource