CVE-2009-0040

Modified
Published: 22 Feb 2009, 22:00
Last modified:07 Aug 2024, 04:17

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
6.8 MEDIUM
v2.0 (nvd)
EPSS Score
8.28% LOW
8% probability -0.21%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

22 Feb 2009, 22:00
Published
Vulnerability first disclosed
07 Aug 2024, 04:17
Last Modified
Vulnerability information updated

Description

The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.

CVSS Metrics

  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 8.28% Percentile: 92%

Techniques & Countermeasures

  • CWE-824Access of Uninitialized Pointer

    The product accesses or uses a pointer that has not been initialized.

Affected Systems

  • appleiphone_os

    < 3.0

  • applemac_os_x

    < 10.5.8

  • debiandebian_linux

    4.0 | 5.0

  • fedoraprojectfedora

    9 | 10

  • libpnglibpng

    < 1.0.43 | ≥ 1.2.0, < 1.2.35

  • opensuseopensuse

    10.3 | 11.0 | 11.1

  • suselinux_enterprise

    9.0 | 10.0

  • suselinux_enterprise_desktop

    10:sp2

  • suselinux_enterprise_server

    10:sp2

References (82)