CVE-2005-3662 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Roelofs Pnmtopng
Severity
4.6MEDIUMNVD
EPSS
0.3%
top 48.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 18
Latest updateMay 3
Description
Off-by-one buffer overflow in pnmtopng before 2.39, when using the -alpha command line option (Alphas_Of_Color), allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM file with exactly 256 colors.
CVSS vector
AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4