Vulnerability CVE-2009-0040: Information

Description

The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.

Severity: MEDIUM (6.8)

Published: Feb. 23, 2009
Modified: Feb. 9, 2024
Error type identifier: CWE-824

References to Advisories, Solutions, and Tools

Hyperlink
Resource
ftp://ftp.simplesystems.org/pub/png/src/libpng-1.2.34-ADVISORY.txt
  • Broken Link
  • Vendor Advisory
http://downloads.sourceforge.net/libpng/libpng-1.2.34-ADVISORY.txt
  • Product
33976
  • Broken Link
  • Vendor Advisory
http://sourceforge.net/project/shownotes.php?group_id=1689&release_id=662441
  • Broken Link
[png-mng-implement] 20090219 libpng-1.2.35 and libpng-1.0.43 fix security vulnerability
  • Broken Link
33970
  • Broken Link
  • Vendor Advisory
33827
  • Broken Link
  • Third Party Advisory
  • VDB Entry
SUSE-SR:2009:005
  • Mailing List
MDVSA-2009:051
  • Broken Link
34145
  • Broken Link
http://support.avaya.com/japple/css/japple?temp.documentID=366362&temp.productID=154235&temp.releaseID=361845&temp.bucketID=126655&PAGE=Document
  • Broken Link
33990
  • Broken Link
  • Third Party Advisory
  • VDB Entry
34272
  • Broken Link
34210
  • Broken Link
34265
  • Broken Link
http://wiki.rpath.com/Advisories:rPSA-2009-0046
  • Broken Link
GLSA-200903-28
  • Third Party Advisory
MDVSA-2009:075
  • Broken Link
SUSE-SA:2009:012
  • Mailing List
ADV-2009-0632
  • Broken Link
34320
  • Broken Link
FEDORA-2009-2045
  • Mailing List
http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm
  • Broken Link
FEDORA-2009-1976
  • Mailing List
DSA-1750
  • Mailing List
34388
  • Broken Link
FEDORA-2009-2884
  • Mailing List
34324
  • Broken Link
FEDORA-2009-2882
  • Mailing List
SSA:2009-083-02
  • Mailing List
34462
  • Broken Link
34464
  • Broken Link
SSA:2009-083-03
  • Mailing List
MDVSA-2009:083
  • Broken Link
SUSE-SA:2009:023
  • Mailing List
APPLE-SA-2009-05-12
  • Mailing List
TA09-133A
  • Third Party Advisory
  • US Government Resource
35074
  • Broken Link
http://support.apple.com/kb/HT3549
  • Third Party Advisory
ADV-2009-1297
  • Broken Link
http://www.vmware.com/security/advisories/VMSA-2009-0007.html
  • Third Party Advisory
35258
  • Broken Link
ADV-2009-1462
  • Broken Link
ADV-2009-1451
  • Broken Link
259989
  • Broken Link
VU#649212
  • Broken Link
  • Third Party Advisory
  • US Government Resource
35302
  • Broken Link
35379
  • Broken Link
http://support.apple.com/kb/HT3613
  • Third Party Advisory
ADV-2009-1522
  • Broken Link
APPLE-SA-2009-06-08-1
  • Broken Link
  • Mailing List
http://support.avaya.com/elmodocs2/security/ASA-2009-208.htm
  • Broken Link
35386
  • Broken Link
ADV-2009-1560
  • Broken Link
ADV-2009-1621
  • Broken Link
APPLE-SA-2009-06-17-1
  • Mailing List
http://support.apple.com/kb/HT3639
  • Third Party Advisory
ADV-2009-2172
  • Broken Link
http://support.apple.com/kb/HT3757
  • Third Party Advisory
36096
  • Broken Link
APPLE-SA-2009-08-05-1
  • Mailing List
TA09-218A
  • Third Party Advisory
  • US Government Resource
DSA-1830
  • Mailing List
[security-announce] 20090820 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server
  • Broken Link
RHSA-2009:0333
  • Broken Link
RHSA-2009:0315
  • Broken Link
34143
  • Broken Link
RHSA-2009:0325
  • Broken Link
RHSA-2009:0340
  • Broken Link
34137
  • Broken Link
34140
  • Broken Link
34152
  • Broken Link
1020521
  • Broken Link
ADV-2009-0473
  • Broken Link
ADV-2009-0469
  • Broken Link
GLSA-201209-25
  • Third Party Advisory
libpng-pointer-arrays-code-execution(48819)
  • Third Party Advisory
  • VDB Entry
oval:org.mitre.oval:def:6458
  • Broken Link
oval:org.mitre.oval:def:10316
  • Broken Link
20090821 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server
  • Broken Link
  • Third Party Advisory
  • VDB Entry
20090529 VMSA-2009-0007 VMware Hosted products and ESX and ESXi patches resolve security issues
  • Broken Link
  • Third Party Advisory
  • VDB Entry
20090312 rPSA-2009-0046-1 libpng
  • Broken Link
  • Third Party Advisory
  • VDB Entry
    1. Configuration 1

      cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:*
      Start including
      1.2.0
      End excliding
      1.2.35

      cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:*
      End excliding
      1.0.43

      Configuration 2

      cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
      End excliding
      3.0

      cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
      End excliding
      10.5.8

      Configuration 3

      cpe:2.3:o:opensuse:opensuse:11.1:*:*:*:*:*:*:*

      cpe:2.3:o:opensuse:opensuse:11.0:*:*:*:*:*:*:*

      cpe:2.3:o:opensuse:opensuse:10.3:*:*:*:*:*:*:*

      cpe:2.3:o:suse:linux_enterprise_server:10:sp2:*:*:*:*:*:*

      cpe:2.3:o:suse:linux_enterprise_desktop:10:sp2:*:*:*:*:*:*

      cpe:2.3:o:suse:linux_enterprise:10.0:-:*:*:*:*:*:*

      cpe:2.3:o:suse:linux_enterprise:9.0:-:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*

      Configuration 5

      cpe:2.3:o:fedoraproject:fedora:10:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:*