search menu icon-carat-right cmu-wordmark

CERT Coordination Center

libpng png_handle_sPLT() integer overflow

Vulnerability Note VU#477512

Original Release Date: 2004-08-04 | Last Revised: 2005-06-01

Overview

The Portable Network Graphics library (libpng) contains a flaw that could introduce a remotely exploitable vulnerability.

Description

The Portable Network Graphics (PNG) image format is used as an alternative to other image formats such as the Graphics Interchange Format (GIF). The libpng reference library is available for application developers to support the PNG image format.

A potential integer overflow error exists during a memory allocation within the png_handle_sPLT() function. While the code that contains this error introduces a dangerous condition, it is unclear what practical vulnerabilities it might present in applications using libpng.

Multiple applications support the PNG image format, including web browsers, email clients, and various graphic utilities. Because multiple products have used the libpng reference library to implement native PNG image processing, multiple applications will be affected by this issue in different ways.

Impact

The complete impact of this vulnerability is not yet known.

Solution

Apply a patch from the vendor

Patches have been released to address this vulnerability. Please see the Systems Affected section of this document for more details.

Vendor Information

477512
 

View all 40 vendors View less vendors


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to Chris Evans for reporting this vulnerability.

This document was written by Chad Dougherty and Damon Morda.

Other Information

CVE IDs: CVE-2004-0599
Severity Metric: 0.76
Date Public: 2004-08-04
Date First Published: 2004-08-04
Date Last Updated: 2005-06-01 20:45 UTC
Document Revision: 18

Sponsored by CISA.