MEDIUM · 6.8

CVE-2009-0040

The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application ...

Vulnerability Description

The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
LibpngLibpng< 1.0.43
AppleIphone Os< 3.0
AppleMac Os X< 10.5.8
OpensuseOpensuse10.3
SuseLinux Enterprise9.0
SuseLinux Enterprise Desktop10
SuseLinux Enterprise Server10
DebianDebian Linux4.0
FedoraprojectFedora9

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-0040?

CVE-2009-0040 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application ...

How severe is CVE-2009-0040?

CVE-2009-0040 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-0040?

Check the references section above for vendor advisories and patch information. Affected products include: Libpng Libpng, Apple Iphone Os, Apple Mac Os X, Opensuse Opensuse, Suse Linux Enterprise.