CVE-2004-0599: Integer Overflow
Published Aug 5, 2004
·Updated
Multiple integer overflows in the (1) pngreadpng in pngread.c or (2) pnghandlesPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.
Affected Software
1 affected component
Greg Roelofs Libpng<=1.2.5
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Aug 5, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0599?
CVE-2004-0599 is considered a denial of service vulnerability that can cause application crashes.
2
How do I fix CVE-2004-0599?
To fix CVE-2004-0599, upgrade to a patched version of libpng later than 1.2.5.
3
What software is affected by CVE-2004-0599?
CVE-2004-0599 affects libpng versions up to and including 1.2.5.
4
How does CVE-2004-0599 work?
CVE-2004-0599 exploits multiple integer overflows in libpng when handling malicious PNG images.
5
What are the consequences of CVE-2004-0599 exploitation?
Exploitation of CVE-2004-0599 can lead to crashes of applications that use the affected versions of libpng.