HomeLibpngCVE-2008-3964

CVE-2008-3964

UNKNOWN
4.3CVSS
Published: 2008-09-11
Updated: 2025-04-09
AI Analysis

Description

Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the png_push_read_zTXt function in pngread.c, and possibly related to (2) pngtest.c.

CVSS Metrics

Vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Access Vector
network
Access Cmplx
medium
Auth
none
Confidentiality
none
Integrity
none
Availability
partial
Weaknesses
CWE-193

Metadata

Primary Vendor
LIBPNG
Published
9/11/2008
Last Modified
4/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

libpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpng

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief