HomeLibpngCVE-2008-5907

CVE-2008-5907

UNKNOWN
5.0CVSS
Published: 2009-01-15
Updated: 2025-04-09
AI Analysis

Description

The png_check_keyword function in pngwutil.c in libpng before 1.0.42, and 1.2.x before 1.2.34, might allow context-dependent attackers to set the value of an arbitrary memory location to zero via vectors involving creation of crafted PNG files with keywords, related to an implicit cast of the '\0' character constant to a NULL pointer. NOTE: some sources incorrectly report this as a double free vulnerability.

CVSS Metrics

Vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Access Vector
network
Access Cmplx
low
Auth
none
Confidentiality
none
Integrity
partial
Availability
none
Weaknesses
NVD-CWE-noinfo

Metadata

Primary Vendor
LIBPNG
Published
1/15/2009
Last Modified
4/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

libpng : libpnglibpng : libpngdebian : debian_linuxdebian : debian_linux

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2008-5907 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com