MEDIUM · 4.3

CVE-2012-3425

The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (out...

Vulnerability Description

The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large avail_in field value in a PNG image.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
CanonicalUbuntu Linux12.04
LibpngLibpng1.4.0
OpensuseOpensuse11.4
RedhatLibpng1.2.2-16
DebianDebian Linux6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-3425?

CVE-2012-3425 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (out...

How severe is CVE-2012-3425?

CVE-2012-3425 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-3425?

Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Linux, Libpng Libpng, Opensuse Opensuse, Redhat Libpng, Debian Debian Linux.