VDB
CVE-2005-3662
CVE-2005-3662
PUBLISHED
CVSS 4.599999904632568 MEDIUM
Off-by-one buffer overflow in pnmtopng before 2.39, when using the -alpha command line option (Alphas_Of_Color), allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM file with exactly 256 colors.
EPSS 0.60% · 46.1th percentile
Risk Scores
CVSS 2.0
4.599999904632568
EPSS Score
0.60%
46.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| greg_roelofs | pnmtopng | 2.37.3, 2.37.5, 2.37.6 |
| n/a | n/a | n/a |
Timeline
- Nov 18, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- ADV-2005-2418 vdb
- 17828 third-party-advisory
- 18186 third-party-advisory
- USN-218-1 vendor-advisory
- DSA-904 vendor-advisory
- oval:org.mitre.oval:def:9583 vdb
- SUSE-SR:2005:028 vendor-advisory
- 17679 third-party-advisory
- 18517 third-party-advisory
- http://sourceforge.net/project/shownotes.php?release_id=370545 technical
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:217 technical
- http://www.redhat.com/support/errata/RHSA-2005-843.html technical
- http://www.securityfocus.com/bid/15427 technical
- ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U technical
- http://secunia.com/advisories/17544 patch
- https://nvd.nist.gov/vuln/detail/CVE-2005-3662 advisory
- https://usn.ubuntu.com/218-1 url
- http://secunia.com/advisories/17671 url