Buffer overflow in libpng - CVE-2010-1205

 

Buffer overflow in libpng - CVE-2010-1205

Published: June 30, 2010 / Updated: July 29, 2020


Vulnerability identifier: #VU32860
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2010-1205
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.


Affected software

libpng
libpng (Alpine package)

How to mitigate CVE-2010-1205

Install update from vendor's website.

libpng - update to 1.2.44
libpng (Alpine package) - update to 1.4.3-r0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins