CVE-2008-5101Improper Restriction of Operations within the Bounds of a Memory Buffer in Optipng

Severity
9.3CRITICALNVD
EPSS
2.3%
top 15.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 17
Latest updateMay 17

Description

Buffer overflow in the BMP reader in OptiPNG 0.6 and 0.6.1 allows user-assisted attackers to execute arbitrary code via a crafted BMP image, related to an "array overflow."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

Debianoptipng_project/optipng< 0.6.1.1-1+3
NVDoptipng/optipng0.6, 0.6.1+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-cjj9-29x7-jq96: Buffer overflow in the BMP reader in OptiPNG 02022-05-17
OSV
CVE-2008-5101: Buffer overflow in the BMP reader in OptiPNG 02008-11-17
CVEList
CVE-2008-5101: Buffer overflow in the BMP reader in OptiPNG 02008-11-17

📋Vendor Advisories

2
Red Hat
OptiPNG: Buffer overflow in BMP image handling reader2008-10-09
Debian
CVE-2008-5101: optipng - Buffer overflow in the BMP reader in OptiPNG 0.6 and 0.6.1 allows user-assisted ...2008

💬Community

1
Bugzilla
CVE-2008-5101 OptiPNG: Buffer overflow in BMP image handling reader2008-11-12
CVE-2008-5101 — Optipng vulnerability | cvebase