4.3

CVE-2008-3964

Exploit

Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the png_push_read_zTXt function in pngread.c, and possibly related to (2) pngtest.c.

Data is provided by the National Vulnerability Database (NVD)
LibpngLibpng Version < 1.2.32
LibpngLibpng Version1.4.0 Updatebeta1
LibpngLibpng Version1.4.0 Updatebeta10
LibpngLibpng Version1.4.0 Updatebeta11
LibpngLibpng Version1.4.0 Updatebeta12
LibpngLibpng Version1.4.0 Updatebeta13
LibpngLibpng Version1.4.0 Updatebeta14
LibpngLibpng Version1.4.0 Updatebeta15
LibpngLibpng Version1.4.0 Updatebeta16
LibpngLibpng Version1.4.0 Updatebeta17
LibpngLibpng Version1.4.0 Updatebeta18
LibpngLibpng Version1.4.0 Updatebeta19
LibpngLibpng Version1.4.0 Updatebeta2
LibpngLibpng Version1.4.0 Updatebeta20
LibpngLibpng Version1.4.0 Updatebeta21
LibpngLibpng Version1.4.0 Updatebeta22
LibpngLibpng Version1.4.0 Updatebeta23
LibpngLibpng Version1.4.0 Updatebeta24
LibpngLibpng Version1.4.0 Updatebeta25
LibpngLibpng Version1.4.0 Updatebeta26
LibpngLibpng Version1.4.0 Updatebeta27
LibpngLibpng Version1.4.0 Updatebeta28
LibpngLibpng Version1.4.0 Updatebeta29
LibpngLibpng Version1.4.0 Updatebeta3
LibpngLibpng Version1.4.0 Updatebeta30
LibpngLibpng Version1.4.0 Updatebeta31
LibpngLibpng Version1.4.0 Updatebeta32
LibpngLibpng Version1.4.0 Updatebeta33
LibpngLibpng Version1.4.0 Updatebeta4
LibpngLibpng Version1.4.0 Updatebeta5
LibpngLibpng Version1.4.0 Updatebeta6
LibpngLibpng Version1.4.0 Updatebeta7
LibpngLibpng Version1.4.0 Updatebeta8
LibpngLibpng Version1.4.0 Updatebeta9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.68% 0.812
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-193 Off-by-one Error

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

http://www.kb.cert.org/vuls/id/889484
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/31049
Third Party Advisory
VDB Entry