Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

Project Subscriptions

Vendors Products
Iphone Os Subscribe
Mac Os X Subscribe
Mac Os X Server Subscribe
Canonical Subscribe
Ubuntu Linux Subscribe
Debian Linux Subscribe
Fedoraproject Subscribe
Mozilla Subscribe
Firefox Subscribe
Seamonkey Subscribe
Thunderbird Subscribe
Opensuse Subscribe
Opensuse Subscribe
Enterprise Linux Subscribe
Linux Enterprise Server Subscribe
Workstation Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-2072-1 New libpng packages fix several vulnerabilities
Debian DSA Debian DSA DSA-2075-1 New xulrunner packages fix several vulnerabilities
Ubuntu USN Ubuntu USN USN-930-4 Firefox and Xulrunner vulnerabilities
Ubuntu USN Ubuntu USN USN-957-1 Firefox and Xulrunner vulnerabilities
Ubuntu USN Ubuntu USN USN-958-1 Thunderbird vulnerabilities
Ubuntu USN Ubuntu USN USN-960-1 libpng vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://blackberry.com/btsc/KB27244 cve-icon cve-icon
http://code.google.com/p/chromium/issues/detail?id=45983 cve-icon cve-icon
http://googlechromereleases.blogspot.com/2010/07/stable-channel-update.html cve-icon cve-icon
http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=commitdiff%3Bh=188eb6b42602bf7d7ae708a21897923b6a83fe7c#patch18 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044283.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044397.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html cve-icon cve-icon
http://lists.vmware.com/pipermail/security-announce/2010/000105.html cve-icon cve-icon
http://secunia.com/advisories/40302 cve-icon cve-icon
http://secunia.com/advisories/40336 cve-icon cve-icon
http://secunia.com/advisories/40472 cve-icon cve-icon
http://secunia.com/advisories/40547 cve-icon cve-icon
http://secunia.com/advisories/41574 cve-icon cve-icon
http://secunia.com/advisories/42314 cve-icon cve-icon
http://secunia.com/advisories/42317 cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.613061 cve-icon cve-icon
http://support.apple.com/kb/HT4312 cve-icon cve-icon
http://support.apple.com/kb/HT4435 cve-icon cve-icon
http://support.apple.com/kb/HT4456 cve-icon cve-icon
http://support.apple.com/kb/HT4457 cve-icon cve-icon
http://support.apple.com/kb/HT4554 cve-icon cve-icon
http://support.apple.com/kb/HT4566 cve-icon cve-icon
http://trac.webkit.org/changeset/61816 cve-icon cve-icon
http://www.debian.org/security/2010/dsa-2072 cve-icon cve-icon
http://www.libpng.org/pub/png/libpng.html cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2010:133 cve-icon cve-icon
http://www.mozilla.org/security/announce/2010/mfsa2010-41.html cve-icon cve-icon
http://www.securityfocus.com/bid/41174 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-960-1 cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2010-0014.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1612 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1637 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1755 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1837 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1846 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1877 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/2491 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/3045 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/3046 cve-icon cve-icon
https://bugs.webkit.org/show_bug.cgi?id=40798 cve-icon cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=570451 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=608238 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/59815 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2010-1205 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11851 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2010-1205 cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T01:14:06.655Z

Reserved: 2010-03-30T00:00:00

Link: CVE-2010-1205

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2010-06-30T18:30:01.333

Modified: 2025-04-11T00:51:21.963

Link: CVE-2010-1205

cve-icon Redhat

Severity : Critical

Publid Date: 2010-06-25T00:00:00Z

Links: CVE-2010-1205 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses