CVE Database
/

CVE-2010-0205

Back to search

CVE-2010-0205

Published: Mar 3, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2010-0517
vdb-entry
x_refsource_VUPEN
ADV-2010-0682
vdb-entry
x_refsource_VUPEN
62670
vdb-entry
x_refsource_OSVDB
MDVSA-2010:063
vendor-advisory
x_refsource_MANDRIVA
ADV-2010-0605
vdb-entry
x_refsource_VUPEN
FEDORA-2010-3414
vendor-advisory
x_refsource_FEDORA
ADV-2010-0626
vdb-entry
x_refsource_VUPEN
ADV-2010-0686
vdb-entry
x_refsource_VUPEN
39251
third-party-advisory
x_refsource_SECUNIA
ADV-2010-1107
vdb-entry
x_refsource_VUPEN
MDVSA-2010:064
vendor-advisory
x_refsource_MANDRIVA
SUSE-SR:2010:011
vendor-advisory
x_refsource_SUSE
USN-913-1
vendor-advisory
x_refsource_UBUNTU
APPLE-SA-2010-11-10-1
vendor-advisory
x_refsource_APPLE
SUSE-SR:2010:013
vendor-advisory
x_refsource_SUSE
DSA-2032
vendor-advisory
x_refsource_DEBIAN
41574
third-party-advisory
x_refsource_SECUNIA
FEDORA-2010-3375
vendor-advisory
x_refsource_FEDORA
38774
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2010:012
vendor-advisory
x_refsource_SUSE
ADV-2010-0637
vdb-entry
x_refsource_VUPEN
VU#576029
third-party-advisory
x_refsource_CERT-VN
FEDORA-2010-4683
vendor-advisory
x_refsource_FEDORA
38478
vdb-entry
x_refsource_BID
ADV-2010-2491
vdb-entry
x_refsource_VUPEN
1023674
vdb-entry
x_refsource_SECTRACK
ADV-2010-0847
vdb-entry
x_refsource_VUPEN
ADV-2010-0667
vdb-entry
x_refsource_VUPEN
FEDORA-2010-2988
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now