CVE编号
CVE-2009-0040利用情况
暂无补丁情况
官方补丁披露时间
2009-02-23漏洞描述
在1.0.43之前的PNG reference library(也称为libpng)和1.2.35之前的1.2.x,如pngcrush和其他应用程序中所使用的,允许依赖于上下文的攻击者导致拒绝服务(应用程序崩溃)或可能通过精心设计的PNG文件执行任意代码。(该文件触发(1)png_read_png函数,(2) pCAL chunk处理或(3)16位 16-bit gamma tables的设置中没有未初始化的指针。)解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接 |
|
---|---|
ftp://ftp.simplesystems.org/pub/png/src/libpng-1.2.34-ADVISORY.txt | |
http://downloads.sourceforge.net/libpng/libpng-1.2.34-ADVISORY.txt | |
http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html | |
http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html | |
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html | |
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html | |
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html | |
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.html | |
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00009.html | |
http://lists.vmware.com/pipermail/security-announce/2009/000062.html | |
http://secunia.com/advisories/33970 | |
http://secunia.com/advisories/33976 | |
http://secunia.com/advisories/34137 | |
http://secunia.com/advisories/34140 | |
http://secunia.com/advisories/34143 | |
http://secunia.com/advisories/34145 | |
http://secunia.com/advisories/34152 | |
http://secunia.com/advisories/34210 | |
http://secunia.com/advisories/34265 | |
http://secunia.com/advisories/34272 | |
http://secunia.com/advisories/34320 | |
http://secunia.com/advisories/34324 | |
http://secunia.com/advisories/34388 | |
http://secunia.com/advisories/34462 | |
http://secunia.com/advisories/34464 | |
http://secunia.com/advisories/35074 | |
http://secunia.com/advisories/35258 | |
http://secunia.com/advisories/35302 | |
http://secunia.com/advisories/35379 | |
http://secunia.com/advisories/35386 | |
http://secunia.com/advisories/36096 | |
http://security.gentoo.org/glsa/glsa-200903-28.xml | |
http://security.gentoo.org/glsa/glsa-201209-25.xml | |
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackw... | |
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackw... | |
http://sourceforge.net/mailarchive/message.php?msg_name=e56ccc8f0902181726i20... | |
http://sourceforge.net/project/shownotes.php?group_id=1689&release_id=662441 | |
http://sunsolve.sun.com/search/document.do?assetkey=1-66-259989-1 | |
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020521.1-1 | |
http://support.apple.com/kb/HT3549 | |
http://support.apple.com/kb/HT3613 | |
http://support.apple.com/kb/HT3639 | |
http://support.apple.com/kb/HT3757 | |
http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm | |
http://support.avaya.com/elmodocs2/security/ASA-2009-208.htm | |
http://support.avaya.com/japple/css/japple?temp.documentID=366362&temp.produc... | |
http://wiki.rpath.com/Advisories:rPSA-2009-0046 | |
http://www.debian.org/security/2009/dsa-1750 | |
http://www.debian.org/security/2009/dsa-1830 | |
http://www.kb.cert.org/vuls/id/649212 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2009:051 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2009:075 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2009:083 | |
http://www.redhat.com/support/errata/RHSA-2009-0315.html | |
http://www.redhat.com/support/errata/RHSA-2009-0325.html | |
http://www.redhat.com/support/errata/RHSA-2009-0333.html | |
http://www.redhat.com/support/errata/RHSA-2009-0340.html | |
http://www.securityfocus.com/archive/1/501767/100/0/threaded | |
http://www.securityfocus.com/archive/1/503912/100/0/threaded | |
http://www.securityfocus.com/archive/1/505990/100/0/threaded | |
http://www.securityfocus.com/bid/33827 | |
http://www.securityfocus.com/bid/33990 | |
http://www.us-cert.gov/cas/techalerts/TA09-133A.html | |
http://www.us-cert.gov/cas/techalerts/TA09-218A.html | |
http://www.vmware.com/security/advisories/VMSA-2009-0007.html | |
http://www.vupen.com/english/advisories/2009/0469 | |
http://www.vupen.com/english/advisories/2009/0473 | |
http://www.vupen.com/english/advisories/2009/0632 | |
http://www.vupen.com/english/advisories/2009/1297 | |
http://www.vupen.com/english/advisories/2009/1451 | |
http://www.vupen.com/english/advisories/2009/1462 | |
http://www.vupen.com/english/advisories/2009/1522 | |
http://www.vupen.com/english/advisories/2009/1560 | |
http://www.vupen.com/english/advisories/2009/1621 | |
http://www.vupen.com/english/advisories/2009/2172 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/48819 | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova... | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova... | |
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00272.html | |
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00412.html | |
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.html | |
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.html |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
应用 | libpng | libpng | * |
Up to (including) 1.0.42 |
|||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 0.89c | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 0.95 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.0 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.1 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.10 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.11 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.12 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.13 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.14 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.15 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.16 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.17 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.18 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.19 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.2 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.20 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.21 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.22 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.23 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.24 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.25 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.26 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.27 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.28 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.29 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.3 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.30 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.31 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.32 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.33 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.34 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.35 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.37 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.38 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.39 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.40 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.41 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.5 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.6 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.7 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.8 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.0.9 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.0 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.1 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.10 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.11 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.13 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.14 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.15 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.16 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.17 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.18 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.19 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.2 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.20 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.21 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.22 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.23 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.24 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.25 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.26 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.27 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.28 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.29 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.3 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.30 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.31 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.32 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.33 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.34 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.4 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.5 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.6 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.7 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.8 | - | |||||
运行在以下环境 | |||||||||
应用 | libpng | libpng | 1.2.9 | - | |||||
运行在以下环境 | |||||||||
系统 | centos_5 | MozillaFirefox | * |
Up to (excluding) 1.9.0.7-1.el5 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_10.3 | MozillaFirefox | * |
Up to (excluding) 2.0.0.21post-0.1 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_11.0 | MozillaFirefox | * |
Up to (excluding) 3.0.7-1.1 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_11.1 | MozillaFirefox | * |
Up to (excluding) 3.0.7-1.1.6 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_11.4 | MozillaFirefox | * |
Up to (excluding) 24.8.0-127.1 |
|||||
运行在以下环境 | |||||||||
系统 | oracle_5 | MozillaFirefox | * |
Up to (excluding) 1.2.10-7.1.el5_3.2 |
|||||
- 攻击路径 本地
- 攻击复杂度 复杂
- 权限要求 普通权限
- 影响范围 全局影响
- EXP成熟度 未验证
- 补丁情况 官方补丁
- 数据保密性 数据泄露
- 数据完整性 无影响
- 服务器危害 服务器失陷
- 全网数量 N/A
还没有评论,来说两句吧...