2.6

CVE-2006-5793

The sPLT chunk handling code (png_set_sPLT function in pngset.c) in libpng 1.0.6 through 1.2.12 uses a sizeof operator on the wrong data type, which allows context-dependent attackers to cause a denial of service (crash) via malformed sPLT chunks that trigger an out-of-bounds read.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Greg RoelofsLibpng Version1.0.6
Greg RoelofsLibpng Version1.0.7
Greg RoelofsLibpng Version1.0.8
Greg RoelofsLibpng Version1.0.9
Greg RoelofsLibpng Version1.2.0
Greg RoelofsLibpng Version1.2.1
Greg RoelofsLibpng Version1.2.2
Greg RoelofsLibpng Version1.2.3
Greg RoelofsLibpng Version1.2.4
Greg RoelofsLibpng Version1.2.5
Greg RoelofsLibpng Version1.2.6
Greg RoelofsLibpng Version1.2.7
Greg RoelofsLibpng Version1.2.7rc1
Greg RoelofsLibpng Version1.2.8
Greg RoelofsLibpng Version1.2.9
Greg RoelofsLibpng Version1.2.10
Greg RoelofsLibpng Version1.2.11
Greg RoelofsLibpng Version1.2.12
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.33% 0.842
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.