[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-0205Date: (C)2010-03-03   (M)2024-02-22


The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
SECTRACK-1023674
BID-38478
SECUNIA-38774
SECUNIA-39251
SECUNIA-41574
OSVDB-62670
ADV-2010-0517
ADV-2010-0605
ADV-2010-0626
ADV-2010-0637
ADV-2010-0667
ADV-2010-0682
ADV-2010-0686
ADV-2010-0847
ADV-2010-1107
ADV-2010-2491
APPLE-SA-2010-11-10-1
DSA-2032
FEDORA-2010-2988
FEDORA-2010-3375
FEDORA-2010-3414
FEDORA-2010-4683
MDVSA-2010:063
MDVSA-2010:064
SUSE-SR:2010:011
SUSE-SR:2010:012
SUSE-SR:2010:013
USN-913-1
VU#576029
http://lists.vmware.com/pipermail/security-announce/2010/000105.html
http://libpng.sourceforge.net/ADVISORY-1.4.1.html
http://libpng.sourceforge.net/decompression_bombs.html
http://support.apple.com/kb/HT4435
http://www.vmware.com/security/advisories/VMSA-2010-0014.html
libpng-pngdecompresschunk-dos(56661)

CPE    15
cpe:/o:apple:mac_os_x
cpe:/o:opensuse:opensuse:11.1
cpe:/o:opensuse:opensuse:11.0
cpe:/o:opensuse:opensuse:11.2
...
CWE    1
CWE-400
OVAL    26
oval:org.secpod.oval:def:4729
oval:org.secpod.oval:def:300359
oval:org.secpod.oval:def:100427
oval:org.secpod.oval:def:200099
...

© SecPod Technologies