Vulnerability Description
A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libpng | Pngcheck | 2.4.0 |
| Fedoraproject | Extra Packages For Enterprise Linux | 7.0 |
| Fedoraproject | Fedora | 31 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://bodhi.fedoraproject.org/updates/FEDORA-2020-04d5e1ce26Third Party Advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2020-23432b7b72Third Party Advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2020-27b168926aThird Party Advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2020-4349e95c4fThird Party Advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-339db397adThird Party Advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-6c93c61069Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1902011Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/05/msg00043.htmlMailing ListThird Party Advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2020-04d5e1ce26Third Party Advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2020-23432b7b72Third Party Advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2020-27b168926aThird Party Advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2020-4349e95c4fThird Party Advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-339db397adThird Party Advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-6c93c61069Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1902011Issue TrackingThird Party Advisory
FAQ
What is CVE-2020-27818?
CVE-2020-27818 is a vulnerability with a CVSS score of 3.3 (LOW). A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low ris...
How severe is CVE-2020-27818?
CVE-2020-27818 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27818?
Check the references section above for vendor advisories and patch information. Affected products include: Libpng Pngcheck, Fedoraproject Extra Packages For Enterprise Linux, Fedoraproject Fedora, Debian Debian Linux.