CVE-2009-5063
Published Aug 31, 2011
Last updated a year ago
Overview
- Description
- Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a JPEG image containing an iCCP chunk with a negative embedded profile length. NOTE: this is due to an incomplete fix for CVE-2006-7244.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- CWE-401
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6AD38421-81CC-4ACE-8A1B-28FD3FA01E5F", "versionEndIncluding": "1.2.38" }, { "criteria": "cpe:2.3:a:libpng:libpng:1.2.39:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7A704CF6-B833-49ED-A00D-E5C45BC6D3C0" }, { "criteria": "cpe:2.3:a:libpng:libpng:1.2.39:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "348689A3-3699-4045-A663-E7C78F4E6621" }, { "criteria": "cpe:2.3:a:libpng:libpng:1.2.39:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "58D248F0-1403-41E1-83C9-F92B83BAAD31" }, { "criteria": "cpe:2.3:a:libpng:libpng:1.2.39:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F36743A2-E182-4C3F-B06B-55704AD216A1" }, { "criteria": "cpe:2.3:a:libpng:libpng:1.2.39:beta4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "63C628B1-030D-4D3B-9F61-DC70B43A9A34" } ], "operator": "OR" } ] } ]