VDB
CVE-2004-0421
CVE-2004-0421
PUBLISHED
CVSS 5 MEDIUM
The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.
EPSS 4.11% · 89.8th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
4.11%
89.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| redhat | enterprise_linux | 3.0, 2.1 |
| trustix | secure_linux | 2.1, 2.0 |
| redhat | enterprise_linux_desktop | 3.0 |
| redhat | libpng | 1.2.2-16, 1.2.2-20 |
| libpng | libpng | 1.0.9, 1.0.11, 1.0.13 |
| openpkg | openpkg | 1.3, 2.0 |
Timeline
- May 5, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- FEDORA-2004-106 vendor-advisory
- DSA-498 vendor-advisory
- 22958 third-party-advisory
- libpng-png-dos(16022) vdb
- MDKSA-2006:213 vendor-advisory
- MDKSA-2004:040 vendor-advisory
- 10244 vdb
- 22957 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2004-0421 advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11710 url
- http://marc.info/?l=bugtraq&m=108334922320309&w=2 url
- http://marc.info/?l=fedora-announce-list&m=108451350029261&w=2 url
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:212 url
- http://www.redhat.com/support/errata/RHSA-2004-180.html technical
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A971 technical
- http://lists.apple.com/mhonarc/security-announce/msg00056.html technical
- http://marc.info/?l=bugtraq&m=108335030208523&w=2 mailing_list
- http://www.redhat.com/support/errata/RHSA-2004-181.html technical