CVE-2010-1205: Buffer Overflow

Published Jun 25, 2010
·
Updated

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

Other sources

Description of problem:

http://www.libpng.org/pub/png/libpng.html

Several versions of libpng through 1.4.2 (and through 1.2.43 in the older series) contain a bug whereby progressive applications such as web browsers (or the rpng2 demo app included in libpng) could receive an extra row of image data beyond the height reported in the header, potentially leading to an out-of-bounds write to memory (depending on how the application is written) and the possibility of execution of an attacker's code with the privileges of the libpng user (including remote compromise in the case of a libpng-based browser visiting a hostile web site). This vulnerability has been assigned ID CVE-2010-1205 (via Mozilla).

An additional memory-leak bug, involving images with malformed sCAL chunks, is also present; it could lead to an application crash (denial of service) when viewing such images.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce: 1. 2. 3. Actual results:

Expected results:

Additional info:

Red Hat

libpng is vulnerable to a buffer overflow, caused by improper bounds checking by progressive applications when handling image row data. By sending an extra image row data beyond the reported height in the header, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the victim.

IBM

Affected Software

42 affected componentsFixes available
redhat/seamonkey<0:1.0.9-0.57.el3
0:1.0.9-0.57.el3
redhat/libpng<2:1.2.7-3.el4_8.3
2:1.2.7-3.el4_8.3
redhat/libpng10<0:1.0.16-3.el4_8.4
0:1.0.16-3.el4_8.4
redhat/seamonkey<0:1.0.9-60.el4
0:1.0.9-60.el4
redhat/firefox<0:3.6.7-2.el4
0:3.6.7-2.el4
redhat/libpng<2:1.2.10-7.1.el5_5.3
2:1.2.10-7.1.el5_5.3
redhat/thunderbird<0:2.0.0.24-6.el5
0:2.0.0.24-6.el5
redhat/firefox<0:3.6.7-2.el5
0:3.6.7-2.el5
redhat/xulrunner<0:1.9.2.7-2.el5
0:1.9.2.7-2.el5
IBM Cognos Analytics<=12.0.0-12.0.3
IBM Cognos Analytics<=11.2.0-11.2.4 FP4
libpng LIBPNG<1.2.44
libpng LIBPNG>=1.4.0<1.4.3
Google Chrome<5.0.375.99
Apple iTunes<10.2
Apple Safari<5.0.4
Apple iPhone OS>=2.0<=4.1
Apple iOS and macOS>=10.6.0<10.6.4
Apple Mac OS X Server>=10.6.0<10.6.4
Fedoraproject Fedora=12
Fedoraproject Fedora=13
openSUSE openSUSE=11.1
openSUSE openSUSE=11.2
SUSE Linux Enterprise Server=9
SUSE Linux Enterprise Server=10-sp3
SUSE Linux Enterprise Server=11
SUSE Linux Enterprise Server=11-sp1
VMware Player>=2.5<2.5.5
VMware Player>=3.1<3.1.2
VMware Workstation>=6.5.0<6.5.5
VMware Workstation>=7.1<7.1.2
Canonical Ubuntu Linux=6.06
Canonical Ubuntu Linux=8.04
Canonical Ubuntu Linux=9.04
Canonical Ubuntu Linux=9.10
Canonical Ubuntu Linux=10.04
Debian Debian Linux=5.0
Mozilla Firefox<3.5.11
Mozilla Firefox>=3.5.12<3.6.7
Mozilla SeaMonkey<2.0.6
Mozilla Thunderbird<3.0.6
Mozilla Thunderbird>=3.0.7<3.1.1

Event History

Jun 25, 2010
CVE Published
via Red Hat·12:00 AM
Jun 26, 2010
Data Sourced
via Red Hat·09:39 AM
DescriptionSeverityAffected Software
Jun 30, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2010-1205?

CVE-2010-1205 is a high severity vulnerability due to the potential for remote code execution via crafted PNG images.

2

How do I fix CVE-2010-1205?

To fix CVE-2010-1205, update to the latest versions of libpng which are 1.2.44 and later for the 1.2.x series or 1.4.3 and later for the 1.4.x series.

3

Which systems are affected by CVE-2010-1205?

CVE-2010-1205 affects various software packages that utilize libpng versions prior to 1.2.44 and 1.4.3.

4

Can CVE-2010-1205 impact web browsers?

Yes, CVE-2010-1205 can impact web browsers like Firefox and SeaMonkey that use vulnerable versions of libpng.

5

Is CVE-2010-1205 specific to any operating system?

CVE-2010-1205 affects multiple operating systems including Fedora, Red Hat, and Ubuntu, depending on the version of libpng used.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203