CVE-2004-0597
Last modified
CVE-2004-0597 is a vulnerability of currently unknown severity. Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.. EPSS estimates a 82.54% chance of exploitation in the next 30 days.
Description
Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Greg Roelofs | Libpng | <= 1.2.5 |
| Microsoft | Msn Messenger | 6.1 |
| Microsoft | Msn Messenger | 6.2 |
| Microsoft | Windows Media Player | 9 |
| Microsoft | Windows Messenger | 5.0 |
| Microsoft | Windows 98se | All versions |
| Microsoft | Windows Me | All versions |
References
- http://scary.beasts.org/security/CESA-2004-001.txtExploit, Vendor Advisory
- http://www.debian.org/security/2004/dsa-536Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200408-03.xmlPatch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200408-22.xmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/388984Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/817368Third Party Advisory, US Government Resource
- http://www.novell.com/linux/security/advisories/2004_23_libpng.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2004-421.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2004-429.htmlVendor Advisory
- http://www.securityfocus.com/bid/10857Exploit, Patch, Vendor Advisory
- http://www.trustix.net/errata/2004/0040/Patch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-217A.htmlThird Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA05-039A.htmlThird Party Advisory, US Government Resource
- http://scary.beasts.org/security/CESA-2004-001.txtExploit, Vendor Advisory
- http://www.debian.org/security/2004/dsa-536Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200408-03.xmlPatch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200408-22.xmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/388984Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/817368Third Party Advisory, US Government Resource
- http://www.novell.com/linux/security/advisories/2004_23_libpng.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2004-421.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2004-429.htmlVendor Advisory
- http://www.securityfocus.com/bid/10857Exploit, Patch, Vendor Advisory
- http://www.trustix.net/errata/2004/0040/Patch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-217A.htmlThird Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA05-039A.htmlThird Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0597?
How severe is CVE-2004-0597?
How do I fix CVE-2004-0597?
Are you affected by CVE-2004-0597?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
