CVE-2010-0205
published 2010-03-03CVE-2010-0205: The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
4.21%
89.8th percentile
The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.6.5 | 10.6.5 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libpng | libpng | >= 1.0.0 < 1.0.53 | 1.0.53 |
| libpng | libpng | >= 1.2.0 < 1.2.43 | 1.2.43 |
| libpng | libpng | >= 1.4.0 < 1.4.1 | 1.4.1 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| vmware | esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qjvj-64rf-p4qg: The png_decompress_chunk function in pngrutil
ghsa_unreviewed·2022-05-02
CVE-2010-0205 [MEDIUM] CWE-400 GHSA-qjvj-64rf-p4qg: The png_decompress_chunk function in pngrutil
The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.
VMware
VMware Workstation, Player, and ACE address several security issues.
vendor_vmware·2010-09-23·CVSS 2.1
CVE-2010-0205 [LOW] VMware Workstation, Player, and ACE address several security issues.
VMSA-2010-0014: VMware Workstation, Player, and ACE address several security issues.
a. VMware Workstation and Player installer security issue The Workstation 7.x and Player 3.x installers will load an index.htm file located in the current working directory on which Workstation 7.x or Player 3.x is being installed. This may allow an attacker to display a malicious file if they manage to get their file onto the system prior to installation. The issue can only be exploited at the time that Workstation 7.x or Player 3.x is being installed. Installed versions of Workstation and Player are not affected. The security issue is no longer present in the installer of the new versions of Workstation 7.x and Player 3.x (see table below for the version numbers). The Common Vulnerabilities and Exposure
Ubuntu
libpng vulnerabilities
vendor_ubuntu·2010-03-16·CVSS 4.3
CVE-2009-2042 [MEDIUM] libpng vulnerabilities
Title: libpng vulnerabilities
Summary: libpng vulnerabilities
It was discovered that libpng did not properly initialize memory when
decoding certain 1-bit interlaced images. If a user or automated system
were tricked into processing crafted PNG images, an attacker could possibly
use this flaw to read sensitive information stored in memory. This issue
only affected Ubuntu 6.06 LTS, 8.04 LTS, 8.10 and 9.04. (CVE-2009-2042)
It was discovered that libpng did not properly handle certain excessively
compressed PNG images. If a user or automated system were tricked into
processing a crafted PNG image, an attacker could possibly use this flaw to
consume all available resources, resulting in a denial of service.
(CVE-2010-0205)
Instructions: After a standard system upgrade you need to reboot yo
Red Hat
libpng: excessive memory consumption due to highly compressed huge ancillary chunk
vendor_redhat·2010-03-01·CVSS 4.3
CVE-2010-0205 [MEDIUM] CWE-770 libpng: excessive memory consumption due to highly compressed huge ancillary chunk
libpng: excessive memory consumption due to highly compressed huge ancillary chunk
The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.
Package: libpng (Red Hat Enterprise Linux 6) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0205 kernel: futex: refcount issue in case of requeue
bugzilla·2014-05-05·CVSS 6.9
CVE-2014-0205 [MEDIUM] CVE-2014-0205 kernel: futex: refcount issue in case of requeue
CVE-2014-0205 kernel: futex: refcount issue in case of requeue
A flaw was found in the way the Linux kernel's futex subsystem handled
reference counting in case of futex requeue during futex_wait().
An unprivileged local user could use this flaw to crash the system or,
potentially, escalate their privileges on the system by overputting
reference counter on either inode or mm that backs up the memory area of
the futex, leading to use-after-free.
References:
https://lkml.org/lkml/2010/9/16/99
Upstream fix:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=7ada876a8703f23befbb20a7465a702ee39b1704
Acknowledgements:
The security impact of this issue was discovered by Mateusz Guzik of Red Hat.
Discussion:
Statement:
This issue does not affect the Linux kernel pac
Bugzilla
CVE-2010-0205 libpng: excessive memory consumption due to highly compressed huge ancillary chunk
bugzilla·2010-02-17·CVSS 4.3
CVE-2010-0205 [MEDIUM] CVE-2010-0205 libpng: excessive memory consumption due to highly compressed huge ancillary chunk
CVE-2010-0205 libpng: excessive memory consumption due to highly compressed huge ancillary chunk
It was reported that libpng suffers from an issue where certain highly compressed ancillary chunks (zTxt, iTxt, iCCP) could cause libpng to stall or crash by consuming huge amounts of memory. This vulnerability is reported to affect all versions of libpng prior to 1.4.1, as well as versions of Firefox from 3.0. It is also possible that other gecko-based browsers are vulnerable as well, as well as all versions of pngcrush, ImageMagick, and GraphicsMagick.
CERT is tracking this issue as VU#576029.
Discussion:
This issue is public now and assigned the name CVE-2010-0205:
https://www.kb.cert.org/vuls/id/576029
---
Created attachment 397627
patch for fixing extremely slow decompression of com
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://libpng.sourceforge.net/ADVISORY-1.4.1.htmlhttp://libpng.sourceforge.net/decompression_bombs.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037237.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037355.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037364.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037607.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000105.htmlhttp://osvdb.org/62670http://secunia.com/advisories/38774http://secunia.com/advisories/39251http://secunia.com/advisories/41574http://support.apple.com/kb/HT4435http://ubuntu.com/usn/usn-913-1http://www.debian.org/security/2010/dsa-2032http://www.kb.cert.org/vuls/id/576029http://www.mandriva.com/security/advisories?name=MDVSA-2010:063http://www.mandriva.com/security/advisories?name=MDVSA-2010:064http://www.securityfocus.com/bid/38478http://www.securitytracker.com/id?1023674http://www.vmware.com/security/advisories/VMSA-2010-0014.htmlhttp://www.vupen.com/english/advisories/2010/0517http://www.vupen.com/english/advisories/2010/0605http://www.vupen.com/english/advisories/2010/0626http://www.vupen.com/english/advisories/2010/0637http://www.vupen.com/english/advisories/2010/0667http://www.vupen.com/english/advisories/2010/0682http://www.vupen.com/english/advisories/2010/0686http://www.vupen.com/english/advisories/2010/0847http://www.vupen.com/english/advisories/2010/1107http://www.vupen.com/english/advisories/2010/2491https://exchange.xforce.ibmcloud.com/vulnerabilities/56661http://libpng.sourceforge.net/ADVISORY-1.4.1.htmlhttp://libpng.sourceforge.net/decompression_bombs.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037237.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037355.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037364.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037607.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000105.htmlhttp://osvdb.org/62670http://secunia.com/advisories/38774http://secunia.com/advisories/39251http://secunia.com/advisories/41574http://support.apple.com/kb/HT4435http://ubuntu.com/usn/usn-913-1http://www.debian.org/security/2010/dsa-2032http://www.kb.cert.org/vuls/id/576029http://www.mandriva.com/security/advisories?name=MDVSA-2010:063http://www.mandriva.com/security/advisories?name=MDVSA-2010:064http://www.securityfocus.com/bid/38478http://www.securitytracker.com/id?1023674http://www.vmware.com/security/advisories/VMSA-2010-0014.htmlhttp://www.vupen.com/english/advisories/2010/0517http://www.vupen.com/english/advisories/2010/0605http://www.vupen.com/english/advisories/2010/0626http://www.vupen.com/english/advisories/2010/0637http://www.vupen.com/english/advisories/2010/0667http://www.vupen.com/english/advisories/2010/0682http://www.vupen.com/english/advisories/2010/0686http://www.vupen.com/english/advisories/2010/0847http://www.vupen.com/english/advisories/2010/1107http://www.vupen.com/english/advisories/2010/2491https://exchange.xforce.ibmcloud.com/vulnerabilities/56661
2010-03-03
Published