First published: Fri Jul 26 2002(Updated: )
Buffer overflow in the progressive reader for libpng 1.2.x before 1.2.4, and 1.0.x before 1.0.14, allows attackers to cause a denial of service (crash) via a PNG data stream that has more IDAT data than indicated by the IHDR chunk.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libpng | ||
debian/libpng3 | ||
Libpng | =1.2.4 | |
Libpng | =1.0.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0728 is considered a medium severity vulnerability due to its ability to cause denial of service through a buffer overflow.
To fix CVE-2002-0728, update libpng to version 1.2.4 or later for the 1.2.x series, or version 1.0.14 or later for the 1.0.x series.
CVE-2002-0728 affects libpng versions 1.2.x before 1.2.4 and 1.0.x before 1.0.14.
Attackers can exploit CVE-2002-0728 to trigger a buffer overflow, leading to application crashes and denial of service.
CVE-2002-0728 is an older vulnerability, but depending on your system's configuration and software version, it may still pose a risk if outdated versions of libpng are in use.