CVE-2016-10087

Modified
Published: 30 Jan 2017, 22:00
Last modified:06 Aug 2024, 03:07

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.0 (nvd)
EPSS Score
0.93% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jan 2017, 22:00
Published
Vulnerability first disclosed
06 Aug 2024, 03:07
Last Modified
Vulnerability information updated

Description

The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allows context-dependent attackers to cause a NULL pointer dereference vectors involving loading a text chunk into a png structure, removing the text, and then adding another text chunk to the structure.

CVSS Metrics

  • v3.0HIGHScore: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 0.93% Percentile: 76%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • libpnglibpng

    0.8 | 0.71 | 0.81 | 0.82 | 0.85 | 0.86 | 0.87 | 0.88 | 0.89 | 0.89c | 0.90 | 0.95 | 0.96 | 0.97 | 0.98 | 0.99 | 0.99a | 0.99b | 0.99c | 0.99d | 0.99e | 0.99f | 0.99g | 0.99h | 1.00 | 1.0.0a | 1.0.0b | 1.0.1 | 1.0.1a | 1.0.1b | 1.0.1c | 1.0.1d | 1.0.1e | 1.0.2 | 1.0.2a | 1.0.3 | 1.0.3a | 1.0.3b | 1.0.3d | 1.0.4 | 1.0.4a | 1.0.4b | 1.0.4c | 1.0.4d | 1.0.4e | 1.0.4f | 1.0.5 | 1.0.5a | 1.0.5b | 1.0.5c | 1.0.5d | 1.0.5e | 1.0.5f | 1.0.5g | 1.0.5h | 1.0.5i | 1.0.5j | 1.0.5k | 1.0.5l | 1.0.5m | 1.0.5n | 1.0.5o | 1.0.5p | 1.0.5q | 1.0.5r | 1.0.5s | 1.0.5t | 1.0.5u | 1.0.5v | 1.0.6 | 1.0.6d | 1.0.6e | 1.0.6f | 1.0.6g | 1.0.6h | 1.0.6i | 1.0.6j | 1.0.7 | 1.0.8 | 1.0.9 | 1.0.10 | 1.0.11 | 1.0.12 | 1.0.13 | 1.0.14 | 1.0.15 | 1.0.16 | 1.0.17 | 1.0.18 | 1.0.19 | 1.0.20 | 1.0.21 | 1.0.22 | 1.0.23 | 1.0.24 | 1.0.25 | 1.0.26 | 1.0.27 | 1.0.28 | 1.0.29 | 1.0.30 | 1.0.31 | 1.0.32 | 1.0.33 | 1.0.34 | 1.0.35 | 1.0.37 | 1.0.38 | 1.0.39 | 1.0.40 | 1.0.41 | 1.0.42 | 1.0.43 | 1.0.44 | 1.0.45 | 1.0.46 | 1.0.47 | 1.0.48 | 1.0.50 | 1.0.51 | 1.0.52 | 1.0.53 | 1.0.54 | 1.0.55 | 1.0.56 | 1.0.57 | 1.0.58 | 1.0.59 | 1.0.60 | 1.0.61 | 1.0.62 | 1.0.63 | 1.0.64 | 1.0.65 | 1.0.66 | 1.2.0 | 1.2.1 | 1.2.3 | 1.2.4 | 1.2.6 | 1.2.8 | 1.2.10 | 1.2.12 | 1.2.13 | 1.2.14 | 1.2.16 | 1.2.18 | 1.2.20 | 1.2.21 | 1.2.22 | 1.2.24 | 1.2.25 | 1.2.26 | 1.2.27 | 1.2.29 | 1.2.32 | 1.2.33 | 1.2.35 | 1.2.37 | 1.2.38 | 1.2.39 | 1.2.41 | 1.2.42 | 1.2.44 | 1.2.45 | 1.2.46 | 1.2.47 | 1.2.50 | 1.2.51 | 1.2.52 | 1.2.53 | 1.2.54 | 1.2.55 | 1.2.56 | 1.4.0 | 1.4.1 | 1.4.2 | 1.4.3 | 1.4.4 | 1.4.5 | 1.4.6 | 1.4.7 | 1.4.8 | 1.4.9 | 1.4.10 | 1.4.11 | 1.4.12 | 1.4.13 | 1.4.14 | 1.4.15 | 1.4.16 | 1.4.17 | 1.4.18 | 1.4.19 | 1.5.0 | 1.5.1 | 1.5.2 | 1.5.3 | 1.5.4 | 1.5.5 | 1.5.6 | 1.5.7 | 1.5.8 | 1.5.9 | 1.5.10 | 1.5.11 | 1.5.12 | 1.5.13 | 1.5.14 | 1.5.15 | 1.5.16 | 1.5.17 | 1.5.18 | 1.5.19 | 1.5.20 | 1.5.21 | 1.5.22 | 1.5.23 | 1.5.24 | 1.5.25 | 1.5.26 | 1.5.27 | 1.6.0 | 1.6.1 | 1.6.2 | 1.6.3 | 1.6.4 | 1.6.5 | 1.6.6 | 1.6.7 | 1.6.8 | 1.6.9 | 1.6.10 | 1.6.11 | 1.6.12 | 1.6.13 | 1.6.14 | 1.6.15 | 1.6.16 | 1.6.17 | 1.6.18 | 1.6.19 | 1.6.20 | 1.6.21 | 1.6.22 | 1.6.23 | 1.6.24 | 1.6.25 | 1.6.26

References (8)