National Cyber Awareness System
Vulnerability Summary for CVE-2009-0040
Original release date:02/22/2009
Last revised:05/15/2013
Source:
US-CERT/NIST
Overview
The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.
Impact
CVSS Severity (version 2.0):
Impact Subscore:
6.4
Exploitability Subscore:
8.6
CVSS Version 2 Metrics:
Access Vector: Network exploitable
Access Complexity: Medium
Authentication: Not required to exploit
Impact Type:Allows unauthorized disclosure of information; Allows unauthorized modification; Allows disruption of service
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.
US-CERT Technical Alert: TA09-218A
Name: TA09-218A
US-CERT Technical Alert: TA09-133A
Name: TA09-133A
US-CERT Vulnerability Note: VU#649212
Name: VU#649212
External Source: FEDORA
Name: FEDORA-2009-2884
External Source: FEDORA
Name: FEDORA-2009-2882
External Source: FEDORA
Name: FEDORA-2009-1976
External Source: FEDORA
Name: FEDORA-2009-2045
External Source: XF
Name: libpng-pointer-arrays-code-execution(48819)
External Source: VUPEN
Name: ADV-2009-2172
External Source: VUPEN
Name: ADV-2009-1621
External Source: VUPEN
Name: ADV-2009-1560
External Source: VUPEN
Name: ADV-2009-1522
External Source: VUPEN
Name: ADV-2009-1462
External Source: VUPEN
Name: ADV-2009-1451
External Source: VUPEN
Name: ADV-2009-1297
External Source: VUPEN
Name: ADV-2009-0632
External Source: VUPEN
Name: ADV-2009-0473
External Source: VUPEN
Name: ADV-2009-0469
External Source: CONFIRM
Name: http://www.vmware.com/security/advisories/VMSA-2009-0007.html
External Source: BID
Name: 33990
External Source: BID
Name: 33827
External Source: BUGTRAQ
Name: 20090821 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server
External Source: BUGTRAQ
Name: 20090529 VMSA-2009-0007 VMware Hosted products and ESX and ESXi patches resolve security issues
External Source: BUGTRAQ
Name: 20090312 rPSA-2009-0046-1 libpng
External Source: REDHAT
Name: RHSA-2009:0340
External Source: REDHAT
Name: RHSA-2009:0333
External Source: REDHAT
Name: RHSA-2009:0325
External Source: REDHAT
Name: RHSA-2009:0315
External Source: MANDRIVA
Name: MDVSA-2009:083
External Source: MANDRIVA
Name: MDVSA-2009:075
External Source: MANDRIVA
Name: MDVSA-2009:051
External Source: DEBIAN
Name: DSA-1830
External Source: DEBIAN
Name: DSA-1750
External Source: CONFIRM
Name: http://wiki.rpath.com/Advisories:rPSA-2009-0046
External Source: CONFIRM
Name: http://support.avaya.com/japple/css/japple?temp.documentID=366362&temp.productID=154235&temp.releaseID=361845&temp.bucketID=126655&PAGE=Document
External Source: CONFIRM
Name: http://support.avaya.com/elmodocs2/security/ASA-2009-208.htm
External Source: CONFIRM
Name: http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm
External Source: CONFIRM
Name: http://support.apple.com/kb/HT3757
External Source: CONFIRM
Name: http://support.apple.com/kb/HT3639
External Source: CONFIRM
Name: http://support.apple.com/kb/HT3613
External Source: CONFIRM
Name: http://support.apple.com/kb/HT3549
External Source: SUNALERT
Name: 1020521
External Source: SUNALERT
Name: 259989
External Source: CONFIRM
Name: http://sourceforge.net/project/shownotes.php?group_id=1689&release_id=662441
External Source: MLIST
Name: [png-mng-implement] 20090219 libpng-1.2.35 and libpng-1.0.43 fix security vulnerability
External Source: SLACKWARE
Name: SSA:2009-083-03
External Source: SLACKWARE
Name: SSA:2009-083-02
External Source: GENTOO
Name: GLSA-201209-25
External Source: GENTOO
Name: GLSA-200903-28
External Source: SECUNIA
Name: 36096
External Source: SECUNIA
Name: 35386
External Source: SECUNIA
Name: 35379
External Source: SECUNIA
Name: 35302
External Source: SECUNIA
Name: 35258
External Source: SECUNIA
Name: 35074
External Source: SECUNIA
Name: 34464
External Source: SECUNIA
Name: 34462
External Source: SECUNIA
Name: 34388
External Source: SECUNIA
Name: 34324
External Source: SECUNIA
Name: 34320
External Source: SECUNIA
Name: 34272
External Source: SECUNIA
Name: 34265
External Source: SECUNIA
Name: 34210
External Source: SECUNIA
Name: 34152
External Source: SECUNIA
Name: 34145
External Source: SECUNIA
Name: 34143
External Source: SECUNIA
Name: 34140
External Source: SECUNIA
Name: 34137
External Source: SECUNIA
Name: 33976
Type: Advisory
External Source: SECUNIA
Name: 33970
Type: Advisory
External Source: OVAL
Name: oval:org.mitre.oval:def:6458
External Source: OVAL
Name: oval:org.mitre.oval:def:10316
External Source: MLIST
Name: [security-announce] 20090820 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server
External Source: SUSE
Name: SUSE-SA:2009:023
External Source: SUSE
Name: SUSE-SA:2009:012
External Source: SUSE
Name: SUSE-SR:2009:005
External Source: APPLE
Name: APPLE-SA-2009-05-12
External Source: APPLE
Name: APPLE-SA-2009-06-17-1
External Source: APPLE
Name: APPLE-SA-2009-06-08-1
External Source: APPLE
Name: APPLE-SA-2009-08-05-1
External Source: CONFIRM
Name: http://downloads.sourceforge.net/libpng/libpng-1.2.34-ADVISORY.txt
External Source: CONFIRM
Name: ftp://ftp.simplesystems.org/pub/png/src/libpng-1.2.34-ADVISORY.txt
Type: Advisory
References to Check Content
Identifier:oval:org.mitre.oval:def:6458
Check System:http://oval.mitre.org/XMLSchema/oval-definitions-5
Identifier:oval:org.mitre.oval:def:10316
Check System:http://oval.mitre.org/XMLSchema/oval-definitions-5