CVE-2002-1363Improper Restriction of Operations within the Bounds of a Memory Buffer in Roelofs Libpng

5 documents5 sources
Severity
7.5HIGHNVD
EPSS
6.8%
top 8.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 26
Latest updateApr 30

Description

Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDgreg_roelofs/libpng14 versions+13

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c3x2-x88p-4gpx: Portable Network Graphics (PNG) library libpng 12022-04-30
CVEList
CVE-2002-1363: Portable Network Graphics (PNG) library libpng 12004-09-01

📋Vendor Advisories

1
Red Hat
security flaw2002-12-19

💬Community

1
Bugzilla
CVE-2002-1363 security flaw2018-08-16
CVE-2002-1363 — Greg Roelofs Libpng vulnerability | cvebase