Description
The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1750-1 | New libpng packages fix several vulnerabilities |
Debian DSA |
DSA-1830-1 | New icedove packages fix several vulnerabilities |
Ubuntu USN |
USN-728-1 | Firefox and Xulrunner vulnerabilities |
Ubuntu USN |
USN-730-1 | libpng vulnerabilities |
References
History
No history.
Subscriptions
Apple
Subscribe
Iphone Os
Subscribe
Mac Os X
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Libpng
Subscribe
Libpng
Subscribe
Opensuse
Subscribe
Opensuse
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Suse
Subscribe
Linux Enterprise
Subscribe
Linux Enterprise Desktop
Subscribe
Linux Enterprise Server
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T04:17:10.449Z
Reserved: 2008-12-15T00:00:00.000Z
Link: CVE-2009-0040
No data.
Status : Deferred
Published: 2009-02-22T22:30:00.203
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-0040
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN