CVE-2005-3662Improper Restriction of Operations within the Bounds of a Memory Buffer in Roelofs Pnmtopng

Severity
4.6MEDIUMNVD
EPSS
0.3%
top 48.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18
Latest updateMay 3

Description

Off-by-one buffer overflow in pnmtopng before 2.39, when using the -alpha command line option (Alphas_Of_Color), allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM file with exactly 256 colors.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages2 packages

NVDgreg_roelofs/pnmtopng5 versions+4
debiandebian/netpbm-free< netpbm-free 2:10.0-10.1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-69w9-429r-r7vm: Off-by-one buffer overflow in pnmtopng before 22022-05-03
OSV
CVE-2005-3662: Off-by-one buffer overflow in pnmtopng before 22005-11-18

📋Vendor Advisories

3
Ubuntu
netpbm vulnerabilities2005-11-22
Red Hat
security flaw2005-11-12
Debian
CVE-2005-3662: netpbm-free - Off-by-one buffer overflow in pnmtopng before 2.39, when using the -alpha comman...2005

💬Community

2
Bugzilla
CVE-2005-3662 security flaw2018-08-16
Bugzilla
CVE-2005-3662 netpbm off by one error2005-11-16