← Back

CVE-2008-3964

nvd nist
Published: Sep 11, 2008Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the png_push_read_zTXt function in pngread.c, and possibly related to (2) pngtest.c.

Affected (34)

Products: Libpng: Libpng
1 product
Libpng
Configuration A
34 vulnerable
Vulnerable SoftwareAffected Versions
Libpng
Before 1.2.32
Version 1.4.0 beta10
Version 1.4.0 beta11
Version 1.4.0 beta12
Version 1.4.0 beta13
Version 1.4.0 beta14
Version 1.4.0 beta15
Version 1.4.0 beta16
Version 1.4.0 beta17
Version 1.4.0 beta18
Version 1.4.0 beta19
Version 1.4.0 beta1
Version 1.4.0 beta20
Version 1.4.0 beta21
Version 1.4.0 beta22
Version 1.4.0 beta23
Version 1.4.0 beta24
Version 1.4.0 beta25
Version 1.4.0 beta26
Version 1.4.0 beta27
Version 1.4.0 beta28
Version 1.4.0 beta29
Version 1.4.0 beta2
Version 1.4.0 beta30
Version 1.4.0 beta31
Version 1.4.0 beta32
Version 1.4.0 beta33
Version 1.4.0 beta3
Version 1.4.0 beta4
Version 1.4.0 beta5
Version 1.4.0 beta6
Version 1.4.0 beta7
Version 1.4.0 beta8
Version 1.4.0 beta9

References (42)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Permissions Required
Source: cve@mitre.org
Permissions Required
Source: cve@mitre.org
Permissions Required
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkPatch
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.