{"vuid":"VU#286464","idnumber":"286464","name":"libpng contains integer overflows in progressive display image reading","keywords":["libpng","progressive reading","integer overflow"],"overview":"The Portable Network Graphics library (libpng) contains several flaws in progressive image handling that could introduce a remotely exploitable vulnerability.","clean_desc":"The Portable Network Graphics (PNG) image format is used as an alternative to other image formats such as the Graphics Interchange Format (GIF). The libpng reference library is available for application developers to support the PNG image format. The libpng library features the ability to display interlaced, or progressive display, PNG files or streams. A number of potential integer overflow errors exist in libpng's handling of such progressive display images. While the code that contains these errors introduces dangerous conditions, it is unclear what practical vulnerabilities it might present in applications using libpng. Multiple applications support the PNG image format, including web browsers, email clients, and various graphic utilities. Because multiple products have used the libpng reference library to implement native PNG image processing, multiple applications will be affected by this issue in different ways.","impact":"The complete impact of this vulnerability is not yet known.","resolution":"Apply a patch from the vendor Patches have been released to address this vulnerability. Please see the Systems Affected section of this document for more details.","workarounds":"","sysaffected":"","thanks":"Thanks to Chris Evans for reporting this vulnerability.","author":"This document was written by Chad Dougherty and Damon Morda.","public":["http://scary.beasts.org/security/CESA-2004-001.txt","http://www.libpng.org/pub/png/","http://libpng.sourceforge.net/"],"cveids":["CVE-2004-0599"],"certadvisory":"","uscerttechnicalalert":null,"datecreated":"2004-07-16T14:42:55Z","publicdate":"2004-08-04T00:00:00Z","datefirstpublished":"2004-08-04T16:05:01Z","dateupdated":"2005-06-01T21:40:55Z","revision":14,"vrda_d1_directreport":"0","vrda_d1_population":"2","vrda_d1_impact":"3","cam_widelyknown":"7","cam_exploitation":"0","cam_internetinfrastructure":"5","cam_population":"15","cam_impact":"3","cam_easeofexploitation":"8","cam_attackeraccessrequired":"12","cam_scorecurrent":"0.972","cam_scorecurrentwidelyknown":"2.025","cam_scorecurrentwidelyknownexploited":"3.645","ipprotocol":"","cvss_accessvector":"","cvss_accesscomplexity":"","cvss_authentication":null,"cvss_confidentialityimpact":"","cvss_integrityimpact":"","cvss_availabilityimpact":"","cvss_exploitablity":null,"cvss_remediationlevel":"","cvss_reportconfidence":"","cvss_collateraldamagepotential":"","cvss_targetdistribution":"","cvss_securityrequirementscr":"","cvss_securityrequirementsir":"","cvss_securityrequirementsar":"","cvss_basescore":"","cvss_basevector":"","cvss_temporalscore":"","cvss_environmentalscore":"","cvss_environmentalvector":"","metric":0.972,"vulnote":null}