imPC@ndo IT

Tracker / CVE-2010-1205

CVE-2010-1205

Critical 9.8

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

Affected products and versions

apple iphone_os · 2.0 → 4.1
apple itunes · … → 10.2
apple mac_os_x · 10.6.0 → 10.6.4
apple mac_os_x_server · 10.6.0 → 10.6.4
apple safari · … → 5.0.4
canonical ubuntu_linux
debian debian_linux
fedoraproject fedora
google chrome · … → 5.0.375.99
libpng libpng · … → 1.2.44
libpng libpng · 1.4.0 → 1.4.3
mozilla firefox · … → 3.5.11
mozilla firefox · 3.5.12 → 3.6.7
mozilla seamonkey · … → 2.0.6
mozilla thunderbird · … → 3.0.6
mozilla thunderbird · 3.0.7 → 3.1.1
opensuse opensuse
suse linux_enterprise_server
vmware player · 2.5 → 2.5.5
vmware player · 3.1 → 3.1.2
vmware workstation · 6.5.0 → 6.5.5
vmware workstation · 7.1 → 7.1.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References