CVE-2008-1382

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
14/04/2008
Last modified:
09/04/2025

Description

libpng 1.0.6 through 1.0.32, 1.2.0 through 1.2.26, and 1.4.0beta01 through 1.4.0beta19 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PNG file with zero length "unknown" chunks, which trigger an access of uninitialized memory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libpng:libpng:1.0.6:a:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.0.6:d:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.0.6:e:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.0.6:f:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.0.6:g:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.0.6:h:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.0.6:i:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.0.6:j:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.0.7:beta11:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.0.7:beta12:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.0.7:beta13:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.0.7:beta14:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.0.7:beta15:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.0.7:beta16:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.0.7:beta17:*:*:*:*:*:*


References to Advisories, Solutions, and Tools