CVE-2008-3964

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2008
Last modified:
09/04/2025

Description

Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the png_push_read_zTXt function in pngread.c, and possibly related to (2) pngtest.c.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* 1.2.32 (excluding)
cpe:2.3:a:libpng:libpng:1.4.0:beta1:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.4.0:beta10:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.4.0:beta11:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.4.0:beta12:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.4.0:beta13:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.4.0:beta14:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.4.0:beta15:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.4.0:beta16:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.4.0:beta17:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.4.0:beta18:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.4.0:beta19:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.4.0:beta2:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.4.0:beta20:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.4.0:beta21:*:*:*:*:*:*


References to Advisories, Solutions, and Tools