CVE Database
/

CVE-2007-5269

Back to search

CVE-2007-5269

Published: Oct 8, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Certain chunk handlers in libpng before 1.0.29 and 1.2.x before 1.2.21 allow remote attackers to cause a denial of service (crash) via crafted (1) pCAL (png_handle_pCAL), (2) sCAL (png_handle_sCAL), (3) tEXt (png_push_read_tEXt), (4) iTXt (png_handle_iTXt), and (5) ztXT (png_handle_ztXt) chunking in PNG images, which trigger out-of-bounds read operations.

VendorProductVersions

n/a

n/a

affected
n/a

References

27965
third-party-advisory
x_refsource_SECUNIA
MDKSA-2007:217
vendor-advisory
x_refsource_MANDRIVA
35386
third-party-advisory
x_refsource_SECUNIA
FEDORA-2007-2666
vendor-advisory
x_refsource_FEDORA
GLSA-201209-25
vendor-advisory
x_refsource_GENTOO
FEDORA-2007-2521
vendor-advisory
x_refsource_FEDORA
27093
third-party-advisory
x_refsource_SECUNIA
1020521
vendor-advisory
x_refsource_SUNALERT
ADV-2009-1560
vdb-entry
x_refsource_VUPEN
34388
third-party-advisory
x_refsource_SECUNIA
ADV-2009-1462
vdb-entry
x_refsource_VUPEN
27662
third-party-advisory
x_refsource_SECUNIA
31712
third-party-advisory
x_refsource_SECUNIA
FEDORA-2007-734
vendor-advisory
x_refsource_FEDORA
27529
third-party-advisory
x_refsource_SECUNIA
27405
third-party-advisory
x_refsource_SECUNIA
27746
third-party-advisory
x_refsource_SECUNIA
RHSA-2007:0992
vendor-advisory
x_refsource_REDHAT
ADV-2007-3390
vdb-entry
x_refsource_VUPEN
259989
vendor-advisory
x_refsource_SUNALERT
35302
third-party-advisory
x_refsource_SECUNIA
31713
third-party-advisory
x_refsource_SECUNIA
ADV-2008-0924
vdb-entry
x_refsource_VUPEN
TA08-150A
third-party-advisory
x_refsource_CERT
27391
third-party-advisory
x_refsource_SECUNIA
25956
vdb-entry
x_refsource_BID
SUSE-SR:2007:025
vendor-advisory
x_refsource_SUSE
27369
third-party-advisory
x_refsource_SECUNIA
1018849
vdb-entry
x_refsource_SECTRACK
oval:org.mitre.oval:def:10614
vdb-entry
signature
x_refsource_OVAL
27492
third-party-advisory
x_refsource_SECUNIA
29420
third-party-advisory
x_refsource_SECUNIA
APPLE-SA-2008-03-18
vendor-advisory
x_refsource_APPLE
27284
third-party-advisory
x_refsource_SECUNIA
30430
third-party-advisory
x_refsource_SECUNIA
USN-538-1
vendor-advisory
x_refsource_UBUNTU
APPLE-SA-2008-05-28
vendor-advisory
x_refsource_APPLE
30161
third-party-advisory
x_refsource_SECUNIA
GLSA-200805-07
vendor-advisory
x_refsource_GENTOO
DSA-1750
vendor-advisory
x_refsource_DEBIAN
GLSA-200711-08
vendor-advisory
x_refsource_GENTOO
ADV-2008-0905
vdb-entry
x_refsource_VUPEN
ADV-2008-1697
vdb-entry
x_refsource_VUPEN
SSA:2007-325-01
vendor-advisory
x_refsource_SLACKWARE
20071112 FLEA-2007-0065-1 libpng
mailing-list
x_refsource_BUGTRAQ
28276
vdb-entry
x_refsource_BID
ADV-2008-2466
vdb-entry
x_refsource_VUPEN
27629
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now