[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-3328Date: (C)2012-01-17   (M)2024-04-30


The png_handle_cHRM function in pngrutil.c in libpng 1.5.4, when color-correction support is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed PNG image containing a cHRM chunk associated with a certain zero value.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.6
Exploit Score: 4.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
APPLE-SA-2012-02-01-1
APPLE-SA-2012-05-09-1
APPLE-SA-2012-09-19-1
VU#477046
http://libpng.org/pub/png/libpng.html
http://sourceforge.net/tracker/index.php?func=detail&aid=3406145&group_id=5624&atid=105624
http://support.apple.com/kb/HT5130
http://support.apple.com/kb/HT5281
http://support.apple.com/kb/HT5503
https://bugzilla.redhat.com/show_bug.cgi?id=740864

OVAL    3
oval:org.secpod.oval:def:3902
oval:org.secpod.oval:def:5820
oval:org.secpod.oval:def:3930

© SecPod Technologies