6.8

CVE-2009-0040

The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LibpngLibpng Version < 1.0.43
LibpngLibpng Version >= 1.2.0 < 1.2.35
AppleiPhone OS Version < 3.0
ApplemacOS X Version < 10.5.8
OpensuseOpensuse Version10.3
OpensuseOpensuse Version11.0
OpensuseOpensuse Version11.1
SuseLinux Enterprise Version9.0 Update-
SuseLinux Enterprise Version10.0 Update-
SuseLinux Enterprise Desktop Version10 Updatesp2
SuseLinux Enterprise Server Version10 Updatesp2
DebianDebian Linux Version4.0
DebianDebian Linux Version5.0
FedoraprojectFedora Version9
FedoraprojectFedora Version10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.28% 0.92
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-824 Access of Uninitialized Pointer

The product accesses or uses a pointer that has not been initialized.

http://www.us-cert.gov/cas/techalerts/TA09-133A.html
Third Party Advisory
US Government Resource
http://www.securityfocus.com/archive/1/505990/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.us-cert.gov/cas/techalerts/TA09-218A.html
Third Party Advisory
US Government Resource
http://www.securityfocus.com/archive/1/503912/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/archive/1/501767/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://secunia.com/advisories/33970
Vendor Advisory
Broken Link
http://secunia.com/advisories/33976
Vendor Advisory
Broken Link
http://www.kb.cert.org/vuls/id/649212
Third Party Advisory
US Government Resource
Broken Link
http://www.securityfocus.com/bid/33827
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/33990
Third Party Advisory
Broken Link
VDB Entry