9.8

CVE-2010-1205

Exploit
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libpng ≫ Libpng Version < 1.2.44
Libpng ≫ Libpng Version >= 1.4.0 < 1.4.3
Google ≫ Chrome Version < 5.0.375.99
Apple ≫ iTunes Version < 10.2
Apple ≫ Safari Version < 5.0.4
Apple ≫ iPhone OS Version >= 2.0 <= 4.1
Apple ≫ macOS X Version >= 10.6.0 < 10.6.4
Apple ≫ macOS X Server Version >= 10.6.0 < 10.6.4
Fedoraproject ≫ Fedora Version 12
Fedoraproject ≫ Fedora Version 13
Opensuse ≫ Opensuse Version 11.1
Opensuse ≫ Opensuse Version 11.2
Suse ≫ Linux Enterprise Server Version 10 Update sp3
Suse ≫ Linux Enterprise Server Version 11 Update -
Suse ≫ Linux Enterprise Server Version 11 Update sp1
VMware ≫ Player Version >= 2.5 < 2.5.5
VMware ≫ Player Version >= 3.1 < 3.1.2
VMware ≫ Workstation Version >= 6.5.0 < 6.5.5
VMware ≫ Workstation Version >= 7.1 < 7.1.2
Canonical ≫ Ubuntu Linux Version 6.06
Canonical ≫ Ubuntu Linux Version 8.04
Canonical ≫ Ubuntu Linux Version 9.04
Canonical ≫ Ubuntu Linux Version 9.10
Canonical ≫ Ubuntu Linux Version 10.04 SwEdition -
Debian ≫ Debian Linux Version 5.0
Mozilla ≫ Firefox Version < 3.5.11
Mozilla ≫ Firefox Version >= 3.5.12 < 3.6.7
Mozilla ≫ Seamonkey Version < 2.0.6
Mozilla ≫ Thunderbird Version < 3.0.6
Mozilla ≫ Thunderbird Version >= 3.0.7 < 3.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 43.38% 0.986
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html
Third Party Advisory
Mailing List
http://support.apple.com/kb/HT4435
Broken Link
http://www.mandriva.com/security/advisories?name=MDVSA-2010:133
Broken Link
http://www.vupen.com/english/advisories/2010/1837
Broken Link
http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html
Third Party Advisory
Mailing List
http://secunia.com/advisories/42314
Broken Link
http://support.apple.com/kb/HT4456
Third Party Advisory
http://www.vupen.com/english/advisories/2010/3046
Broken Link
http://www.libpng.org/pub/png/libpng.html
Vendor Advisory
Product
http://lists.vmware.com/pipermail/security-announce/2010/000105.html
Patch
Third Party Advisory
Mailing List
http://secunia.com/advisories/41574
Broken Link
http://www.vmware.com/security/advisories/VMSA-2010-0014.html
Patch
Third Party Advisory
http://www.vupen.com/english/advisories/2010/2491
Broken Link
http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html
Third Party Advisory
Mailing List
http://support.apple.com/kb/HT4312
Third Party Advisory
http://blackberry.com/btsc/KB27244
Broken Link
http://code.google.com/p/chromium/issues/detail?id=45983
Third Party Advisory
Exploit
Mailing List
Issue Tracking
http://googlechromereleases.blogspot.com/2010/07/stable-channel-update.html
Third Party Advisory
Release Notes
http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=commitdiff%3Bh=188eb6b42602bf7d7ae708a21897923b6a83fe7c#patch18
http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html
Third Party Advisory
Mailing List
http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html
Third Party Advisory
Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044283.html
Third Party Advisory
Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044397.html
Third Party Advisory
Mailing List
http://secunia.com/advisories/40302
Broken Link
http://secunia.com/advisories/40336
Broken Link
http://secunia.com/advisories/40472
Broken Link
http://secunia.com/advisories/40547
Broken Link
http://secunia.com/advisories/42317
Broken Link
http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.613061
Patch
Third Party Advisory
Mailing List
http://support.apple.com/kb/HT4457
Third Party Advisory
http://support.apple.com/kb/HT4554
Third Party Advisory
http://support.apple.com/kb/HT4566
Broken Link
http://trac.webkit.org/changeset/61816
Patch
Third Party Advisory
http://www.debian.org/security/2010/dsa-2072
Third Party Advisory
http://www.mozilla.org/security/announce/2010/mfsa2010-41.html
Third Party Advisory
http://www.securityfocus.com/bid/41174
Third Party Advisory
VDB Entry
http://www.ubuntu.com/usn/USN-960-1
Third Party Advisory
http://www.vupen.com/english/advisories/2010/1612
Broken Link
http://www.vupen.com/english/advisories/2010/1637
Broken Link
http://www.vupen.com/english/advisories/2010/1755
Broken Link
http://www.vupen.com/english/advisories/2010/1846
Broken Link
http://www.vupen.com/english/advisories/2010/1877
Broken Link
http://www.vupen.com/english/advisories/2010/3045
Broken Link
https://bugs.webkit.org/show_bug.cgi?id=40798
Third Party Advisory
Permissions Required
https://bugzilla.mozilla.org/show_bug.cgi?id=570451
Third Party Advisory
Exploit
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=608238
Patch
Third Party Advisory
Issue Tracking
https://exchange.xforce.ibmcloud.com/vulnerabilities/59815
Third Party Advisory
VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11851
Third Party Advisory