CVE-2006-0481
published 2006-01-31CVE-2006-0481: Heap-based buffer overflow in the alpha strip capability in libpng 1.2.7 allows context-dependent attackers to cause a denial of service (crash) when the…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.01%
85.9th percentile
Heap-based buffer overflow in the alpha strip capability in libpng 1.2.7 allows context-dependent attackers to cause a denial of service (crash) when the png_do_strip_filler function is used to strip alpha channels out of the image.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| greg_roelofs | libpng | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g542-vx79-g9v8: Heap-based buffer overflow in the alpha strip capability in libpng 1
ghsa_unreviewed·2022-05-03
CVE-2006-0481 [MEDIUM] CWE-119 GHSA-g542-vx79-g9v8: Heap-based buffer overflow in the alpha strip capability in libpng 1
Heap-based buffer overflow in the alpha strip capability in libpng 1.2.7 allows context-dependent attackers to cause a denial of service (crash) when the png_do_strip_filler function is used to strip alpha channels out of the image.
Red Hat
security flaw
vendor_redhat·2004-12-03·CVSS 5.0
CVE-2006-0481 [MEDIUM] security flaw
security flaw
Heap-based buffer overflow in the alpha strip capability in libpng 1.2.7 allows context-dependent attackers to cause a denial of service (crash) when the png_do_strip_filler function is used to strip alpha channels out of the image.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-0481 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2006-0481 [MEDIUM] CVE-2006-0481 security flaw
CVE-2006-0481 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Heap-based buffer overflow in the alpha strip capability in libpng 1.2.7 allows context-dependent attackers to cause a denial of service (crash) when the png_do_strip_filler function is used to strip alpha channels out of the image.
Bugzilla
CVE-2006-0481 libpng heap based buffer overflow
bugzilla·2006-01-31·CVSS 5.0
CVE-2006-0481 [MEDIUM] CVE-2006-0481 libpng heap based buffer overflow
CVE-2006-0481 libpng heap based buffer overflow
libpng heap based buffer overflow
There is a heap based buffer overflow in libpng 1.2.7 only. Upstream
has a note with the release for 1.2.8 that fixes a crash when a
program tries to strip alpha channels out of the image (calling the
png_set_strip_alpha() function during libpng initialization).
It should be noted that this particular libpng feature is only used by
tetex and xemacs within RHEL4, limiting the potential damage the
overflow can cause.
Discussion:
Created attachment 123913
Patch extracted from the upstream 1.2.8 release
---
Created attachment 123914
Testcase
---
I have built libpng-1.2.7-1.el4.2 with the patch, and converted your testcase in
the RHTS test /desktop/libpng/CVE2006-0481, but it doesn't work in RHTS for some
ftp://ftp.simplesystems.org/pub/libpng/png/src/libpng-1.2.8-README.txthttp://secunia.com/advisories/18654http://secunia.com/advisories/18863http://secunia.com/advisories/33137http://security.gentoo.org/glsa/glsa-200812-15.xmlhttp://securitytracker.com/id?1015615http://securitytracker.com/id?1015617http://www.redhat.com/support/errata/RHSA-2006-0205.htmlhttp://www.securityfocus.com/bid/16626http://www.vupen.com/english/advisories/2006/0393https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179455https://exchange.xforce.ibmcloud.com/vulnerabilities/24396https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10780ftp://ftp.simplesystems.org/pub/libpng/png/src/libpng-1.2.8-README.txthttp://secunia.com/advisories/18654http://secunia.com/advisories/18863http://secunia.com/advisories/33137http://security.gentoo.org/glsa/glsa-200812-15.xmlhttp://securitytracker.com/id?1015615http://securitytracker.com/id?1015617http://www.redhat.com/support/errata/RHSA-2006-0205.htmlhttp://www.securityfocus.com/bid/16626http://www.vupen.com/english/advisories/2006/0393https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179455https://exchange.xforce.ibmcloud.com/vulnerabilities/24396https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10780
2006-01-31
Published