VDB
CVE-2008-3964
CVE-2008-3964
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the png_push_read_zTXt function in pngread.c, and possibly related to (2) pngtest.c.
EPSS 3.34% · 87.5th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
3.34%
87.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| libpng | libpng | 1.4.0, 1.4.0, 1.4.0 |
| n/a | n/a | n/a |
Timeline
- Sep 10, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- http://sourceforge.net/project/shownotes.php?group_id=5624&release_id=624517 url
- ADV-2009-1560 vdb
- ADV-2009-1462 vdb
- 259989 vendor-advisory
- [oss-security] 20080909 Re: CVE request (libpng) mailing-list
- ADV-2008-2512 vdb
- GLSA-200812-15 vendor-advisory
- http://sourceforge.net/project/shownotes.php?release_id=624518 url
- http://support.avaya.com/elmodocs2/security/ASA-2009-208.htm url
- [oss-security] 20080909 CVE request (libpng) mailing-list
- 35386 third-party-advisory
- 1020521 vendor-advisory
- libpng-pngpushreadztxt-dos(44928) vdb
- 31049 vdb
- 35302 third-party-advisory
- VU#889484 third-party-advisory
- 31781 third-party-advisory
- 33137 third-party-advisory
- [png-mng-implement] 20080918 libpng-1.0.40 and libpng-1.2.32 available mailing-list
- MDVSA-2009:051 vendor-advisory
…and 2 more