CVE-2002-1363
published 2002-12-26CVE-2002-1363: Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of…
PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.14%
92.6th percentile
Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| greg_roelofs | libpng | — | — |
| greg_roelofs | libpng | — | — |
| greg_roelofs | libpng | — | — |
| greg_roelofs | libpng | — | — |
| greg_roelofs | libpng | — | — |
| greg_roelofs | libpng | — | — |
| greg_roelofs | libpng | — | — |
| greg_roelofs | libpng | — | — |
| greg_roelofs | libpng | — | — |
| greg_roelofs | libpng | — | — |
| greg_roelofs | libpng | — | — |
| greg_roelofs | libpng | — | — |
| greg_roelofs | libpng | — | — |
| greg_roelofs | libpng | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c3x2-x88p-4gpx: Portable Network Graphics (PNG) library libpng 1
ghsa_unreviewed·2022-04-30
CVE-2002-1363 [HIGH] GHSA-c3x2-x88p-4gpx: Portable Network Graphics (PNG) library libpng 1
Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers.
Red Hat
security flaw
vendor_redhat·2002-12-19·CVSS 7.5
CVE-2002-1363 [HIGH] security flaw
security flaw
Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers.
No detection rules found.
No public exploits indexed.
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:008http://www.debian.org/security/2002/dsa-213http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:063http://www.novell.com/linux/security/advisories/2003_004_libpng.htmlhttp://www.redhat.com/support/errata/RHSA-2003-006.htmlhttp://www.redhat.com/support/errata/RHSA-2003-007.htmlhttp://www.redhat.com/support/errata/RHSA-2003-119.htmlhttp://www.redhat.com/support/errata/RHSA-2003-157.htmlhttp://www.redhat.com/support/errata/RHSA-2004-249.htmlhttp://www.redhat.com/support/errata/RHSA-2004-402.htmlhttp://www.securityfocus.com/bid/6431https://bugzilla.fedora.us/show_bug.cgi?id=1943https://exchange.xforce.ibmcloud.com/vulnerabilities/10925https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3657http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:008http://www.debian.org/security/2002/dsa-213http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:063http://www.novell.com/linux/security/advisories/2003_004_libpng.htmlhttp://www.redhat.com/support/errata/RHSA-2003-006.htmlhttp://www.redhat.com/support/errata/RHSA-2003-007.htmlhttp://www.redhat.com/support/errata/RHSA-2003-119.htmlhttp://www.redhat.com/support/errata/RHSA-2003-157.htmlhttp://www.redhat.com/support/errata/RHSA-2004-249.htmlhttp://www.redhat.com/support/errata/RHSA-2004-402.htmlhttp://www.securityfocus.com/bid/6431https://bugzilla.fedora.us/show_bug.cgi?id=1943https://exchange.xforce.ibmcloud.com/vulnerabilities/10925https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3657
2002-12-26
Published