CVE-2012-3425
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
4.3
Description
The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large avail_in field value in a PNG image.
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| ubuntu | 12.04 | affected | |
| ubuntu | 14.04 | affected | |
| ubuntu | 15.04 | affected | |
| ubuntu | 15.10 | affected | |
| suse | 11.4 | affected | |
| suse | 12.1 | affected | |
| debian | 6.0 | affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| libpng | libpng | 1.4.0 | |
| libpng | libpng | 1.4.1 | |
| libpng | libpng | 1.4.2 | |
| libpng | libpng | 1.4.3 | |
| libpng | libpng | 1.4.4 | |
| libpng | libpng | 1.4.5 | |
| libpng | libpng | 1.4.6 | |
| libpng | libpng | 1.4.7 | |
| libpng | libpng | 1.4.8 | |
| libpng | libpng | 1.4.9 | |
| libpng | libpng | 1.2.0 | |
| libpng | libpng | 1.2.1 | |
| libpng | libpng | 1.2.2 | |
| libpng | libpng | 1.2.3 | |
| libpng | libpng | 1.2.4 | |
| libpng | libpng | 1.2.5 | |
| libpng | libpng | 1.2.6 | |
| libpng | libpng | 1.2.7 | |
| libpng | libpng | 1.2.8 | |
| libpng | libpng | 1.2.9 | |
| libpng | libpng | 1.2.10 | |
| libpng | libpng | 1.2.11 | |
| libpng | libpng | 1.2.12 | |
| libpng | libpng | 1.2.13 | |
| libpng | libpng | 1.2.14 | |
| libpng | libpng | 1.2.15 | |
| libpng | libpng | 1.2.16 | |
| libpng | libpng | 1.2.17 | |
| libpng | libpng | 1.2.18 | |
| libpng | libpng | 1.2.19 | |
| libpng | libpng | 1.2.20 | |
| libpng | libpng | 1.2.21 | |
| libpng | libpng | 1.2.22 | |
| libpng | libpng | 1.2.23 | |
| libpng | libpng | 1.2.24 | |
| libpng | libpng | 1.2.25 | |
| libpng | libpng | 1.2.26 | |
| libpng | libpng | 1.2.27 | |
| libpng | libpng | 1.2.28 | |
| libpng | libpng | 1.2.29 | |
| libpng | libpng | 1.2.30 | |
| libpng | libpng | 1.2.31 | |
| libpng | libpng | 1.2.32 | |
| libpng | libpng | 1.2.33 | |
| libpng | libpng | 1.2.34 | |
| libpng | libpng | 1.2.35 | |
| libpng | libpng | 1.2.36 | |
| libpng | libpng | 1.2.37 | |
| libpng | libpng | 1.2.38 | |
| libpng | libpng | 1.2.39 | |
| libpng | libpng | 1.2.40 | |
| libpng | libpng | 1.2.41 | |
| libpng | libpng | 1.2.42 | |
| libpng | libpng | 1.2.43 | |
| libpng | libpng | 1.2.44 | |
| libpng | libpng | 1.2.45 | |
| libpng | libpng | 1.2.46 | |
| libpng | libpng | 1.2.47 | |
| libpng | libpng | 1.2.48 | |
| redhat | libpng | 1.2.2-16 | |
| redhat | libpng | 1.2.2-20 | |
| libpng | libpng | 1.5.0 | |
| libpng | libpng | 1.5.1 | |
| libpng | libpng | 1.5.2 | |
| libpng | libpng | 1.5.3 | |
| libpng | libpng | 1.5.4 | |
| libpng | libpng | 1.5.5 | |
| libpng | libpng | 1.5.6 | |
| libpng | libpng | 1.5.7 | |
| libpng | libpng | 1.5.8 | |
| libpng | libpng | 1.5.9 | |
| libpng | libpng | 1.5.10 | |
| libpng | libpng | 1.0.0 | |
| libpng | libpng | 1.0.1 | |
| libpng | libpng | 1.0.2 | |
| libpng | libpng | 1.0.3 | |
| libpng | libpng | 1.0.5 | |
| libpng | libpng | 1.0.6 | |
| libpng | libpng | 1.0.7 | |
| libpng | libpng | 1.0.8 | |
| libpng | libpng | 1.0.9 | |
| libpng | libpng | 1.0.10 | |
| libpng | libpng | 1.0.11 | |
| libpng | libpng | 1.0.12 | |
| libpng | libpng | 1.0.13 | |
| libpng | libpng | 1.0.14 | |
| libpng | libpng | 1.0.15 | |
| libpng | libpng | 1.0.16 | |
| libpng | libpng | 1.0.17 | |
| libpng | libpng | 1.0.18 | |
| libpng | libpng | 1.0.19 | |
| libpng | libpng | 1.0.20 | |
| libpng | libpng | 1.0.21 | |
| libpng | libpng | 1.0.22 | |
| libpng | libpng | 1.0.23 | |
| libpng | libpng | 1.0.24 | |
| libpng | libpng | 1.0.25 | |
| libpng | libpng | 1.0.26 | |
| libpng | libpng | 1.0.27 | |
| libpng | libpng | 1.0.28 | |
| libpng | libpng | 1.0.29 | |
| libpng | libpng | 1.0.30 | |
| libpng | libpng | 1.0.31 | |
| libpng | libpng | 1.0.32 | |
| libpng | libpng | 1.0.33 | |
| libpng | libpng | 1.0.34 | |
| libpng | libpng | 1.0.35 | |
| libpng | libpng | 1.0.37 | |
| libpng | libpng | 1.0.38 | |
| libpng | libpng | 1.0.39 | |
| libpng | libpng | 1.0.40 | |
| libpng | libpng | 1.0.41 | |
| libpng | libpng | 1.0.42 | |
| libpng | libpng | 1.0.43 | |
| libpng | libpng | 1.0.44 | |
| libpng | libpng | 1.0.45 | |
| libpng | libpng | 1.0.46 | |
| libpng | libpng | 1.0.47 | |
| libpng | libpng | 1.0.48 | |
| libpng | libpng | 1.0.50 | |
| libpng | libpng | 1.0.51 | |
| libpng | libpng | 1.0.52 | |
| libpng | libpng | 1.0.53 | |
| libpng | libpng | 1.0.54 | |
| libpng | libpng | 1.0.55 | |
| libpng | libpng | 1.0.56 | |
| libpng | libpng | 1.0.57 | |
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=668082
- http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=blob%3Bf=CHANGES%3Bh=284de253b1561b976291ba7405acd71ae71ff597%3Bhb=refs/heads/libpng10
- http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=blob%3Bf=CHANGES%3Bh=2da5a7a8b690e257f94353b5b49d493cdc385322%3Bhb=refs/heads/libpng14
- http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=blob%3Bf=CHANGES%3Bh=73e2ffd6a1471f2144d0ce7165d7323cb109f10f%3Bhb=refs/heads/libpng15
- http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=blob%3Bf=CHANGES%3Bhb=a4b640865ae47986bbe71ecc0e7d5181dcb0bac8
- http://lists.opensuse.org/opensuse-updates/2012-08/msg00004.html
- http://www.openwall.com/lists/oss-security/2012/07/24/3
- http://www.openwall.com/lists/oss-security/2012/07/24/5
- http://www.ubuntu.com/usn/USN-2815-1
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=668082
- http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=blob%3Bf=CHANGES%3Bh=284de253b1561b976291ba7405acd71ae71ff597%3Bhb=refs/heads/libpng10
- http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=blob%3Bf=CHANGES%3Bh=2da5a7a8b690e257f94353b5b49d493cdc385322%3Bhb=refs/heads/libpng14
- http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=blob%3Bf=CHANGES%3Bh=73e2ffd6a1471f2144d0ce7165d7323cb109f10f%3Bhb=refs/heads/libpng15
- http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=blob%3Bf=CHANGES%3Bhb=a4b640865ae47986bbe71ecc0e7d5181dcb0bac8
- http://lists.opensuse.org/opensuse-updates/2012-08/msg00004.html
- http://www.openwall.com/lists/oss-security/2012/07/24/3
- http://www.openwall.com/lists/oss-security/2012/07/24/5
- http://www.ubuntu.com/usn/USN-2815-1
CWEs
CWE-119
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.