TROYANOSYVIRUS
Voltar para CVEs

CVE-2010-2249

MEDIUM
6.5

Descricao

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.

Detalhes CVE

Pontuacao CVSS v3.16.5
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioREQUIRED
Publicado6/30/2010
Ultima modificacao4/29/2026
Fontenvd
Avistamentos honeypot0

Produtos afetados

apple:iphone_osapple:itunesapple:safariapple:tvoscanonical:ubuntu_linuxdebian:debian_linuxfedoraproject:fedoralibpng:libpngopensuse:opensusesuse:linux_enterprise_servervmware:playervmware:workstation

Fraquezas (CWE)

CWE-401

Referencias

http://secunia.com/advisories/40302(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/40336(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/40472(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/40547(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/41574(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/42314(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/42317(af854a3a-2127-422b-91ae-364da2661108)
http://support.apple.com/kb/HT4435(af854a3a-2127-422b-91ae-364da2661108)
http://support.apple.com/kb/HT4456(af854a3a-2127-422b-91ae-364da2661108)
http://support.apple.com/kb/HT4457(af854a3a-2127-422b-91ae-364da2661108)
http://support.apple.com/kb/HT4554(af854a3a-2127-422b-91ae-364da2661108)
http://support.apple.com/kb/HT4566(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2010/dsa-2072(af854a3a-2127-422b-91ae-364da2661108)
http://www.libpng.org/pub/png/libpng.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/41174(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id?1024723(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-960-1(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2010/1612(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2010/1637(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2010/1755(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2010/1837(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2010/1846(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2010/1877(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2010/2491(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2010/3045(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2010/3046(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=608644(af854a3a-2127-422b-91ae-364da2661108)

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.