CVE-2005-3662: Buffer Overflow
Off-by-one buffer overflow in pnmtopng before 2.39, when using the -alpha command line option (AlphasOfColor), allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM file with exactly 256 colors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3662?
CVE-2005-3662 has a medium severity level due to potential denial of service and arbitrary code execution risks.
How do I fix CVE-2005-3662?
To mitigate CVE-2005-3662, users should upgrade to pnmtopng version 2.39 or later.
What causes the vulnerability CVE-2005-3662?
CVE-2005-3662 is caused by an off-by-one buffer overflow when using the -alpha command line option with specifically crafted PNM files.
Is CVE-2005-3662 exploitable remotely?
Yes, CVE-2005-3662 can be exploited remotely through crafted PNM files sent to vulnerable systems.
What versions of pnmtopng are affected by CVE-2005-3662?
CVE-2005-3662 affects pnmtopng versions prior to 2.39, including 2.37.3, 2.38, 2.37.6, 2.37.5, and 2.37.4.