CVE-2004-0599
published 2004-11-23CVE-2004-0599: Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading…
PriorityP418medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
6.20%
92.7th percentile
Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| greg_roelofs | libpng | <= 1.2.5 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xpw2-c8vq-gfg3: Multiple integer overflows in the (1) png_read_png in pngread
ghsa_unreviewed·2022-05-03
CVE-2004-0599 [MEDIUM] GHSA-xpw2-c8vq-gfg3: Multiple integer overflows in the (1) png_read_png in pngread
Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.
Red Hat
security flaw
vendor_redhat·2004-08-04·CVSS 5.0
CVE-2004-0599 [MEDIUM] security flaw
security flaw
Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.
No detection rules found.
No public exploits indexed.
arXiv
LLM-Assisted Proactive Threat Intelligence for Automated Reasoning
arxiv_fulltext·2025-04-01
LLM-Assisted Proactive Threat Intelligence for Automated Reasoning
LLM-Assisted Proactive Threat Intelligence for Automated Reasoning
Shuva Paul, Member, IEEE,
Farhad Alemi, Student Member, IEEE,
and Richard Macwan, Member, IEEE
Farhad Alemi is a graduate researcher at Arizona State University.
Shuva Paul and Richard Macwan are researchers at the National Renewable Energy Laboratory, Golden, CO
Journal of \ Class Files, Vol. 14, No. 8, August 2015
Shell et al.: Bare Demo of IEEEtran.cls for IEEE Journals
## Abstract
Successful defense against dynamically evolving cyber threats requires advanced and sophisticated techniques. This research presents a novel approach to enhance real-time cybersecurity threat detection and response by integrating large language models (LLMs) and Retrieval-Augmented Generation (RAG) systems with continuous threat intelligen
Bugzilla
CVE-2004-0599 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2004-0599 [MEDIUM] CVE-2004-0599 security flaw
CVE-2004-0599 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txthttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000856http://lists.apple.com/mhonarc/security-announce/msg00056.htmlhttp://marc.info/?l=bugtraq&m=109163866717909&w=2http://marc.info/?l=bugtraq&m=109181639602978&w=2http://marc.info/?l=bugtraq&m=109761239318458&w=2http://marc.info/?l=bugtraq&m=109900315219363&w=2http://scary.beasts.org/security/CESA-2004-001.txthttp://secunia.com/advisories/22957http://secunia.com/advisories/22958http://sunsolve.sun.com/search/document.do?assetkey=1-66-200663-1http://www.debian.org/security/2004/dsa-536http://www.debian.org/security/2004/dsa-570http://www.debian.org/security/2004/dsa-571http://www.gentoo.org/security/en/glsa/glsa-200408-03.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200408-22.xmlhttp://www.kb.cert.org/vuls/id/160448http://www.kb.cert.org/vuls/id/286464http://www.kb.cert.org/vuls/id/477512http://www.mandriva.com/security/advisories?name=MDKSA-2004:079http://www.mandriva.com/security/advisories?name=MDKSA-2006:212http://www.mandriva.com/security/advisories?name=MDKSA-2006:213http://www.mozilla.org/projects/security/known-vulnerabilities.htmlhttp://www.novell.com/linux/security/advisories/2004_23_libpng.htmlhttp://www.redhat.com/support/errata/RHSA-2004-402.htmlhttp://www.redhat.com/support/errata/RHSA-2004-421.htmlhttp://www.redhat.com/support/errata/RHSA-2004-429.htmlhttp://www.securityfocus.com/bid/10857http://www.securityfocus.com/bid/15495http://www.trustix.net/errata/2004/0040/http://www.us-cert.gov/cas/techalerts/TA04-217A.htmlhttps://bugzilla.fedora.us/show_bug.cgi?id=1943https://exchange.xforce.ibmcloud.com/vulnerabilities/16896https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10938https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1479ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txthttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000856http://lists.apple.com/mhonarc/security-announce/msg00056.htmlhttp://marc.info/?l=bugtraq&m=109163866717909&w=2http://marc.info/?l=bugtraq&m=109181639602978&w=2http://marc.info/?l=bugtraq&m=109761239318458&w=2http://marc.info/?l=bugtraq&m=109900315219363&w=2http://scary.beasts.org/security/CESA-2004-001.txthttp://secunia.com/advisories/22957http://secunia.com/advisories/22958http://sunsolve.sun.com/search/document.do?assetkey=1-66-200663-1http://www.debian.org/security/2004/dsa-536http://www.debian.org/security/2004/dsa-570http://www.debian.org/security/2004/dsa-571http://www.gentoo.org/security/en/glsa/glsa-200408-03.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200408-22.xmlhttp://www.kb.cert.org/vuls/id/160448http://www.kb.cert.org/vuls/id/286464http://www.kb.cert.org/vuls/id/477512http://www.mandriva.com/security/advisories?name=MDKSA-2004:079http://www.mandriva.com/security/advisories?name=MDKSA-2006:212http://www.mandriva.com/security/advisories?name=MDKSA-2006:213http://www.mozilla.org/projects/security/known-vulnerabilities.htmlhttp://www.novell.com/linux/security/advisories/2004_23_libpng.htmlhttp://www.redhat.com/support/errata/RHSA-2004-402.htmlhttp://www.redhat.com/support/errata/RHSA-2004-421.htmlhttp://www.redhat.com/support/errata/RHSA-2004-429.htmlhttp://www.securityfocus.com/bid/10857http://www.securityfocus.com/bid/15495http://www.trustix.net/errata/2004/0040/http://www.us-cert.gov/cas/techalerts/TA04-217A.htmlhttps://bugzilla.fedora.us/show_bug.cgi?id=1943https://exchange.xforce.ibmcloud.com/vulnerabilities/16896https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10938https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1479
2004-11-23
Published