CVE-2007-5268
published 2007-10-08CVE-2007-5268: pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.09%
86.4th percentile
pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG image.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| libpng | libpng | < 1.0.29 | 1.0.29 |
| libpng | libpng | >= 1.2.0 < 1.2.21 | 1.2.21 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libpng vulnerabilities
vendor_ubuntu·2009-03-06·CVSS 4.3
CVE-2008-5907 [MEDIUM] libpng vulnerabilities
Title: libpng vulnerabilities
Summary: libpng vulnerabilities
It was discovered that libpng did not properly perform bounds checking in
certain operations. An attacker could send a specially crafted PNG image and
cause a denial of service in applications linked against libpng. This issue
only affected Ubuntu 8.04 LTS. (CVE-2007-5268, CVE-2007-5269)
Tavis Ormandy discovered that libpng did not properly initialize memory. If a
user or automated system were tricked into opening a crafted PNG image, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileges of the user invoking the program.
This issue did not affect Ubuntu 8.10. (CVE-2008-1382)
Harald van Dijk discovered an off-by-one error in libpng. An attacker could
could ca
Ubuntu
libpng vulnerabilities
vendor_ubuntu·2007-10-25
CVE-2007-5268 libpng vulnerabilities
Title: libpng vulnerabilities
Summary: libpng vulnerabilities
It was discovered that libpng did not properly perform bounds checking
and comparisons in certain operations. An attacker could send a specially
crafted PNG image and cause a denial of service in applications linked
against libpng.
Instructions: After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Red Hat
libpng possible DoS / crash
vendor_redhat·2007-09-11·CVSS 4.3
CVE-2007-5268 [MEDIUM] libpng possible DoS / crash
libpng possible DoS / crash
pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG image.
Statement: Not vulnerable. This issue did not affect the versions of libpng and libpng10 as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
GHSA
GHSA-mpjr-rfjg-826r: pngrtran
ghsa_unreviewed·2022-05-01
CVE-2007-5268 [MEDIUM] GHSA-mpjr-rfjg-826r: pngrtran
pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG image.
No detection rules found.
No public exploits indexed.
http://android-developers.blogspot.com/2008/03/android-sdk-update-m5-rc15-released.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=195261http://docs.info.apple.com/article.html?artnum=307562http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://secunia.com/advisories/27093http://secunia.com/advisories/27284http://secunia.com/advisories/27405http://secunia.com/advisories/27529http://secunia.com/advisories/27629http://secunia.com/advisories/27746http://secunia.com/advisories/29420http://secunia.com/advisories/30161http://secunia.com/advisories/30430http://secunia.com/advisories/35302http://secunia.com/advisories/35386http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.520323http://sourceforge.net/mailarchive/forum.php?thread_name=3.0.6.32.20071004082318.012a7628%40mail.comcast.net&forum_name=png-mng-implementhttp://sourceforge.net/mailarchive/message.php?msg_name=5122753600C3E94F87FBDFFCC090D1FF0400EBC5%40MERCMBX07.na.sas.comhttp://sourceforge.net/mailarchive/message.php?msg_name=e56ccc8f0709140846k24e9a040r81623783b6b1c00f%40mail.gmail.comhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-259989-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020521.1-1http://support.avaya.com/elmodocs2/security/ASA-2009-208.htmhttp://www.coresecurity.com/?action=item&id=2148http://www.gentoo.org/security/en/glsa/glsa-200711-08.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200805-07.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:217http://www.securityfocus.com/archive/1/483582/100/0/threadedhttp://www.securityfocus.com/archive/1/489135/100/0/threadedhttp://www.securityfocus.com/bid/25956http://www.ubuntu.com/usn/usn-538-1http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlhttp://www.vupen.com/english/advisories/2007/3390http://www.vupen.com/english/advisories/2008/0924/referenceshttp://www.vupen.com/english/advisories/2008/1697http://www.vupen.com/english/advisories/2009/1462http://www.vupen.com/english/advisories/2009/1560https://issues.rpath.com/browse/RPL-1814http://android-developers.blogspot.com/2008/03/android-sdk-update-m5-rc15-released.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=195261http://docs.info.apple.com/article.html?artnum=307562http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://secunia.com/advisories/27093http://secunia.com/advisories/27284http://secunia.com/advisories/27405http://secunia.com/advisories/27529http://secunia.com/advisories/27629http://secunia.com/advisories/27746http://secunia.com/advisories/29420http://secunia.com/advisories/30161http://secunia.com/advisories/30430http://secunia.com/advisories/35302http://secunia.com/advisories/35386http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.520323http://sourceforge.net/mailarchive/forum.php?thread_name=3.0.6.32.20071004082318.012a7628%40mail.comcast.net&forum_name=png-mng-implementhttp://sourceforge.net/mailarchive/message.php?msg_name=5122753600C3E94F87FBDFFCC090D1FF0400EBC5%40MERCMBX07.na.sas.comhttp://sourceforge.net/mailarchive/message.php?msg_name=e56ccc8f0709140846k24e9a040r81623783b6b1c00f%40mail.gmail.comhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-259989-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020521.1-1http://support.avaya.com/elmodocs2/security/ASA-2009-208.htmhttp://www.coresecurity.com/?action=item&id=2148http://www.gentoo.org/security/en/glsa/glsa-200711-08.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200805-07.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:217http://www.securityfocus.com/archive/1/483582/100/0/threadedhttp://www.securityfocus.com/archive/1/489135/100/0/threadedhttp://www.securityfocus.com/bid/25956http://www.ubuntu.com/usn/usn-538-1http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlhttp://www.vupen.com/english/advisories/2007/3390http://www.vupen.com/english/advisories/2008/0924/referenceshttp://www.vupen.com/english/advisories/2008/1697http://www.vupen.com/english/advisories/2009/1462http://www.vupen.com/english/advisories/2009/1560https://issues.rpath.com/browse/RPL-1814
2007-10-08
Published