CVE-2004-0421
published 2004-08-18CVE-2004-0421: The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that…
PriorityP414medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.11%
89.6th percentile
The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | >= 1.0.0 < 1.0.55 | 1.0.55 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8m2c-g35f-jj8v: The png_format_buffer function in pngerror
ghsa_unreviewed·2022-05-13·CVSS 5.0
CVE-2011-2501 [MEDIUM] CWE-125 GHSA-8m2c-g35f-jj8v: The png_format_buffer function in pngerror
The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a CVE-2004-0421 regression. NOTE: this is called an off-by-one error by some sources.
GHSA
GHSA-f6gc-489h-x492: The Portable Network Graphics library (libpng) 1
ghsa_unreviewed·2022-04-29
CVE-2004-0421 [MEDIUM] CWE-125 GHSA-f6gc-489h-x492: The Portable Network Graphics library (libpng) 1
The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.
Red Hat
libpng: regression of CVE-2004-0421 in 1.2.23+
vendor_redhat·2011-06-07·CVSS 5.0
CVE-2011-2501 [MEDIUM] libpng: regression of CVE-2004-0421 in 1.2.23+
libpng: regression of CVE-2004-0421 in 1.2.23+
The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a CVE-2004-0421 regression. NOTE: this is called an off-by-one error by some sources.
Red Hat
CAN-2004-0421 libpng can access out of bounds memory
vendor_redhat·2004-04-29·CVSS 5.0
CVE-2004-0421 [MEDIUM] CAN-2004-0421 libpng can access out of bounds memory
CAN-2004-0421 libpng can access out of bounds memory
The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
bugzilla·2011-06-29·CVSS 5.0
CVE-2011-2501 [MEDIUM] CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=717084
Please note: this issue affects multiple
Bugzilla
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
bugzilla·2011-06-29·CVSS 5.0
CVE-2011-2501 [MEDIUM] CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=717084
Please note: this issue affects multiple
Bugzilla
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
bugzilla·2011-06-29·CVSS 5.0
CVE-2011-2501 [MEDIUM] CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=717084
Please note: this issue affects multiple
Bugzilla
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [epel-5]
bugzilla·2011-06-29·CVSS 5.0
CVE-2011-2501 [MEDIUM] CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [epel-5]
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [epel-5]
epel-5 tracking bug for mingw32-libpng: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
mingw32-libpng-1.2.37-2.el5 has been submitted as an update for Fedora EPEL 5.
https://admin.fedoraproject.org/updates/mingw32-libpng-1.2.37-2.el5
---
mingw32-libpng-1.2.37-3.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/mingw32-libpng-1.2.37-3.el6
---
Package mingw32-libpng-1.2.37-2.el5:
* should fix your issue,
* was pushed to the Fedora EPEL 5 testing repository,
* should be available at your local mirro
Bugzilla
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [epel-6]
bugzilla·2011-06-29·CVSS 5.0
CVE-2011-2501 [MEDIUM] CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [epel-6]
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [epel-6]
epel-6 tracking bug for libpng10: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
mingw32-libpng-1.2.37-3.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/mingw32-libpng-1.2.37-3.el6
---
libpng10-1.0.54-3.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/libpng10-1.0.54-3.el6
---
Package mingw32-libpng-1.2.37-3.el6:
* should fix your issue,
* was pushed to the Fedora EPEL 6 testing repository,
* should be available at your local mirror within two days.
Bugzilla
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+
bugzilla·2011-06-27·CVSS 5.0
CVE-2011-2501 [MEDIUM] CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+
It was reported [1] that the fix for CVE-2004-0421 in libpng was inadvertently reverted during the 1.2.23 development cycle. The original flaw could be used to cause a denial of service via a carefully-crafted PNG image.
This would affect all versions of libpng >=1.2.23, including 1.4.x and 1.5.x.
[1] http://sourceforge.net/mailarchive/forum.php?thread_name=BANLkTikrnU6FJNQYFvwmt78hwpgKPVRd1Q%40mail.gmail.com&forum_name=png-mng-implement
Discussion:
Upstream fix is here:
http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commitdiff;h=65e6d5a34f49acdb362a0625a706c6b914e670af
---
This has been assigned CVE-2011-2501:
http://www.openwall.com/lists/oss-security/2011/06/28/16
---
Created libpng tracking bugs
Bugzilla
CVE CAN-2004-0421 - possible out-of-bounds read in the error message handler
bugzilla·2004-05-03
[MEDIUM] CVE CAN-2004-0421 - possible out-of-bounds read in the error message handler
CVE CAN-2004-0421 - possible out-of-bounds read in the error message handler
Description of problem:
CVE CAN-2004-0421 - possible out-of-bounds read in the error message
handler, see http://www.securitytracker.com/alerts/2004/Apr/1009991.html
Version-Release number of selected component (if applicable):
libpng-1.2.2
Actual results:
See bug #121229 (same issue at RHEL) and bug #121750 (update to 1.2.5
and same issue at Fedora Core 2/Development Tree).
Expected results:
Fix (and optional a upgrade to 1.2.5).
Additional info:
A rebuild from RHEL's latest libpng should work as well as a rebuild
of the solution described in #121750.
Discussion:
*** This bug has been marked as a duplicate of 121750 ***
---
Changed to 'CLOSED' state since 'RESOLVED' has been deprecated.
http://lists.apple.com/mhonarc/security-announce/msg00056.htmlhttp://marc.info/?l=bugtraq&m=108334922320309&w=2http://marc.info/?l=bugtraq&m=108335030208523&w=2http://marc.info/?l=fedora-announce-list&m=108451350029261&w=2http://marc.info/?l=fedora-announce-list&m=108451353608968&w=2http://secunia.com/advisories/22957http://secunia.com/advisories/22958http://www.debian.org/security/2004/dsa-498http://www.mandriva.com/security/advisories?name=MDKSA-2004:040http://www.mandriva.com/security/advisories?name=MDKSA-2006:212http://www.mandriva.com/security/advisories?name=MDKSA-2006:213http://www.redhat.com/support/errata/RHSA-2004-180.htmlhttp://www.redhat.com/support/errata/RHSA-2004-181.htmlhttp://www.securityfocus.com/bid/10244https://exchange.xforce.ibmcloud.com/vulnerabilities/16022https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11710https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A971http://lists.apple.com/mhonarc/security-announce/msg00056.htmlhttp://marc.info/?l=bugtraq&m=108334922320309&w=2http://marc.info/?l=bugtraq&m=108335030208523&w=2http://marc.info/?l=fedora-announce-list&m=108451350029261&w=2http://marc.info/?l=fedora-announce-list&m=108451353608968&w=2http://secunia.com/advisories/22957http://secunia.com/advisories/22958http://www.debian.org/security/2004/dsa-498http://www.mandriva.com/security/advisories?name=MDKSA-2004:040http://www.mandriva.com/security/advisories?name=MDKSA-2006:212http://www.mandriva.com/security/advisories?name=MDKSA-2006:213http://www.redhat.com/support/errata/RHSA-2004-180.htmlhttp://www.redhat.com/support/errata/RHSA-2004-181.htmlhttp://www.securityfocus.com/bid/10244https://exchange.xforce.ibmcloud.com/vulnerabilities/16022https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11710https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A971
2004-08-18
Published