CVE-2005-2978
Last modified
CVE-2005-2978 is a vulnerability of currently unknown severity. pnmtopng in netpbm before 10.25, when using the -trans option, uses uninitialized size and index variables when converting Portable Anymap (PNM) images to Portable Network Graphics (PNG), which might allow attackers to execute arbitrary code by modifying the stack.. EPSS estimates a 4.87% chance of exploitation in the next 30 days.
Description
pnmtopng in netpbm before 10.25, when using the -trans option, uses uninitialized size and index variables when converting Portable Anymap (PNM) images to Portable Network Graphics (PNG), which might allow attackers to execute arbitrary code by modifying the stack.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netpbm | Netpbm | 10.0 |
| Netpbm | Netpbm | 10.1 |
| Netpbm | Netpbm | 10.2 |
| Netpbm | Netpbm | 10.3 |
| Netpbm | Netpbm | 10.4 |
| Netpbm | Netpbm | 10.5 |
| Netpbm | Netpbm | 10.6 |
| Netpbm | Netpbm | 10.7 |
| Netpbm | Netpbm | 10.8 |
| Netpbm | Netpbm | 10.9 |
| Netpbm | Netpbm | 10.10 |
| Netpbm | Netpbm | 10.11 |
| Netpbm | Netpbm | 10.12 |
| Netpbm | Netpbm | 10.13 |
| Netpbm | Netpbm | 10.14 |
| Netpbm | Netpbm | 10.15 |
| Netpbm | Netpbm | 10.16 |
| Netpbm | Netpbm | 10.17 |
| Netpbm | Netpbm | 10.18 |
| Netpbm | Netpbm | 10.19 |
| Netpbm | Netpbm | 10.20 |
| Netpbm | Netpbm | 10.21 |
| Netpbm | Netpbm | 10.22 |
| Netpbm | Netpbm | 10.23 |
| Netpbm | Netpbm | 10.24 |
References
- http://www.redhat.com/support/errata/RHSA-2005-793.htmlVendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=168278Exploit, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-793.htmlVendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=168278Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-2978?
How severe is CVE-2005-2978?
How do I fix CVE-2005-2978?
Are you affected by CVE-2005-2978?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
