CVE-2008-3964: Medium severity libp2p vulnerability
Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the pngpushreadzTXt function in pngread.c, and possibly related to (2) pngtest.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3964?
CVE-2008-3964 has a moderate severity level due to its potential to cause denial of service (crash) in affected systems.
How do I fix CVE-2008-3964?
To fix CVE-2008-3964, upgrade to libpng version 1.2.32 or later, or 1.4.0beta34 or later.
What software is affected by CVE-2008-3964?
CVE-2008-3964 affects versions of libpng prior to 1.2.32beta01 and 1.4 up to 1.4.0beta33.
What type of attack is possible with CVE-2008-3964?
CVE-2008-3964 allows context-dependent attackers to craft PNG images that can result in application crashes.
Is CVE-2008-3964 still a concern today?
While CVE-2008-3964 was disclosed in 2008, it remains a concern for systems that use outdated versions of libpng.