CVE-2002-0728
published 2002-08-12CVE-2002-0728: Buffer overflow in the progressive reader for libpng 1.2.x before 1.2.4, and 1.0.x before 1.0.14, allows attackers to cause a denial of service (crash) via a…
PriorityP415medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.09%
79.5th percentile
Buffer overflow in the progressive reader for libpng 1.2.x before 1.2.4, and 1.0.x before 1.0.14, allows attackers to cause a denial of service (crash) via a PNG data stream that has more IDAT data than indicated by the IHDR chunk.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| greg_roelofs | libpng | — | — |
| greg_roelofs | libpng | — | — |
| greg_roelofs | libpng | — | — |
| greg_roelofs | libpng3 | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2002-08-05·CVSS 7.5
CVE-2002-0660 [HIGH] security flaw
security flaw
Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow attackers to cause a denial of service and possibly execute arbitrary code, a different vulnerability than CVE-2002-0728.
Red Hat
security flaw
vendor_redhat·2002-07-08·CVSS 5.0
CVE-2002-0728 [MEDIUM] security flaw
security flaw
Buffer overflow in the progressive reader for libpng 1.2.x before 1.2.4, and 1.0.x before 1.0.14, allows attackers to cause a denial of service (crash) via a PNG data stream that has more IDAT data than indicated by the IHDR chunk.
GHSA
GHSA-hm75-38g4-x8xm: Buffer overflow in the progressive reader for libpng 1
ghsa_unreviewed·2022-05-03
CVE-2002-0728 [MEDIUM] GHSA-hm75-38g4-x8xm: Buffer overflow in the progressive reader for libpng 1
Buffer overflow in the progressive reader for libpng 1.2.x before 1.2.4, and 1.0.x before 1.0.14, allows attackers to cause a denial of service (crash) via a PNG data stream that has more IDAT data than indicated by the IHDR chunk.
GHSA
GHSA-qv23-5x46-j87h: Buffer overflow in libpng 1
ghsa_unreviewed·2022-04-30·CVSS 5.0
CVE-2002-0660 [MEDIUM] GHSA-qv23-5x46-j87h: Buffer overflow in libpng 1
Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow attackers to cause a denial of service and possibly execute arbitrary code, a different vulnerability than CVE-2002-0728.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2002-0728 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2002-0728 [MEDIUM] CVE-2002-0728 security flaw
CVE-2002-0728 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Buffer overflow in the progressive reader for libpng 1.2.x before 1.2.4, and 1.0.x before 1.0.14, allows attackers to cause a denial of service (crash) via a PNG data stream that has more IDAT data than indicated by the IHDR chunk.
Bugzilla
CVE-2002-0660 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2002-0660 [HIGH] CVE-2002-0660 security flaw
CVE-2002-0660 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow attackers to cause a denial of service and possibly execute arbitrary code, a different vulnerability than CVE-2002-0728.
ftp://swrinde.nde.swri.edu/pub/png-group/archives/png-list.200207http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000512http://rhn.redhat.com/errata/RHSA-2002-152.htmlhttp://www.debian.org/security/2002/dsa-140http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-049.phpftp://swrinde.nde.swri.edu/pub/png-group/archives/png-list.200207http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000512http://rhn.redhat.com/errata/RHSA-2002-152.htmlhttp://www.debian.org/security/2002/dsa-140http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-049.php
2002-08-12
Published