Vulnerability Description
pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG image.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libpng | Libpng | < 1.0.29 |
| Canonical | Ubuntu Linux | 6.06 |
References
- http://android-developers.blogspot.com/2008/03/android-sdk-update-m5-rc15-releasThird Party Advisory
- http://bugs.gentoo.org/show_bug.cgi?id=195261Third Party Advisory
- http://docs.info.apple.com/article.html?artnum=307562Third Party Advisory
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlMailing ListThird Party Advisory
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlMailing ListThird Party Advisory
- http://secunia.com/advisories/27093Third Party Advisory
- http://secunia.com/advisories/27284Third Party Advisory
- http://secunia.com/advisories/27405Third Party Advisory
- http://secunia.com/advisories/27529Third Party Advisory
- http://secunia.com/advisories/27629Third Party Advisory
- http://secunia.com/advisories/27746Third Party Advisory
- http://secunia.com/advisories/29420Third Party Advisory
- http://secunia.com/advisories/30161Third Party Advisory
- http://secunia.com/advisories/30430Third Party Advisory
- http://secunia.com/advisories/35302Third Party Advisory
FAQ
What is CVE-2007-5268?
CVE-2007-5268 is a vulnerability with a CVSS score of 4.3 (MEDIUM). pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service ...
How severe is CVE-2007-5268?
CVE-2007-5268 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5268?
Check the references section above for vendor advisories and patch information. Affected products include: Libpng Libpng, Canonical Ubuntu Linux.