CVE-2020-27818
published 2020-12-08CVE-2020-27818: A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a…
PriorityP49low3.3CVSS 3.1
AVLACLPRNUIRSUCNINAL
EPSS
1.21%
65.4th percentile
A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | pngcheck | < pngcheck 2.3.0-13 (bookworm) | pngcheck 2.3.0-13 (bookworm) |
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libpng | pngcheck | — | — |
| libpng | pngcheck | — | — |
| libpng | pngcheck | >= 0 < 2.3.0-13 | 2.3.0-13 |
| libpng | pngcheck | >= 0 < 2.3.0-13 | 2.3.0-13 |
| libpng | pngcheck | >= 0 < 2.3.0-13 | 2.3.0-13 |
| libpng | pngcheck | >= 0 < 2.3.0-13 | 2.3.0-13 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv3.3LOW
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
pngcheck vulnerabilities
vendor_ubuntu·2023-06-21
CVE-2020-27818 pngcheck vulnerabilities
Title: pngcheck vulnerabilities
Summary: Several security issues were fixed in pngcheck.
It was discovered that pngcheck incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-27818: pngcheck - A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attack...
vendor_debian·2020·CVSS 3.3
CVE-2020-27818 [LOW] CVE-2020-27818: pngcheck - A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attack...
A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.
Scope: local
bookworm: resolved (fixed in 2.3.0-13)
bullseye: resolved (fixed in 2.3.0-13)
forky: resolved (fixed in 2.3.0-13)
sid: resolved (fixed in 2.3.0-13)
trixie: resolved (fixed in 2.3.0-13)
GHSA
GHSA-xjm9-9gr6-gcpx: A flaw was found in the check_chunk_name() function of pngcheck-2
ghsa_unreviewed·2022-05-24
CVE-2020-27818 [MEDIUM] CWE-120 GHSA-xjm9-9gr6-gcpx: A flaw was found in the check_chunk_name() function of pngcheck-2
A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.
OSV
CVE-2020-27818: A flaw was found in the check_chunk_name() function of pngcheck-2
osv·2020-12-08·CVSS 3.3
CVE-2020-27818 [LOW] CVE-2020-27818: A flaw was found in the check_chunk_name() function of pngcheck-2
A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bodhi.fedoraproject.org/updates/FEDORA-2020-04d5e1ce26https://bodhi.fedoraproject.org/updates/FEDORA-2020-23432b7b72https://bodhi.fedoraproject.org/updates/FEDORA-2020-27b168926ahttps://bodhi.fedoraproject.org/updates/FEDORA-2020-4349e95c4fhttps://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-339db397adhttps://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-6c93c61069https://bugzilla.redhat.com/show_bug.cgi?id=1902011https://lists.debian.org/debian-lts-announce/2022/05/msg00043.htmlhttps://bodhi.fedoraproject.org/updates/FEDORA-2020-04d5e1ce26https://bodhi.fedoraproject.org/updates/FEDORA-2020-23432b7b72https://bodhi.fedoraproject.org/updates/FEDORA-2020-27b168926ahttps://bodhi.fedoraproject.org/updates/FEDORA-2020-4349e95c4fhttps://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-339db397adhttps://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-6c93c61069https://bugzilla.redhat.com/show_bug.cgi?id=1902011https://lists.debian.org/debian-lts-announce/2022/05/msg00043.html
2020-12-08
Published