Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2010-0205

EPSS 4.58% · P89
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2010-0205

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Libpng png_decompress_chunk()函数拒绝服务漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
libpng是一个可对PNG图形文件实现创建、读写等操作的PNG参考库。 libpng库的png_decompress_chunk()函数在处理包含有高压缩比的辅助数据块的PNG文件时可能会消耗大量的CPU时间和内存,这种资源耗尽可能导致使用libpng库的应用挂起。 PNG格式使用高效的压缩方式来存储图形数据和辅助数据库中的一些相关数据。PNG规范没有限制块的数量,将其大小限制于2.147G(2,147,483,647字节)。类似的,规范将图形的宽度和高度限制到21亿4700万行和21亿4700万列。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2010-0205

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-0205

登录查看更多情报信息。

Same Patch Batch · n/a · 2010-03-03 · 22 CVEs total

CVE-2010-0483Microsoft Internet Explorer winhlp32.exe服务远程代码执行漏洞
CVE-2010-0925Apple Safari CFNetwork 'cfnetwork.dll' SRC 属性拒绝服务漏洞
CVE-2010-0924Apple Safari CFNetwork 'cfnetwork.dll' BACKGROUND属性拒绝服务漏洞
CVE-2010-0923KDE kdebase 'workspace/krunner/lock/lockdlg.cc' 竞争条件漏洞
CVE-2010-0922IBM AIX LDAP 登录本地拒绝服务漏洞
CVE-2010-0921IBM Lotus iNotes 跨站请求伪造漏洞
CVE-2010-0920IBM Lotus iNotes跨站脚本攻击漏洞
CVE-2010-0919IBM Lotus iNotes ActiveX控件URL处理栈溢出漏洞
CVE-2010-0918IBM Lotus iNotes UltraLite多个未明漏洞
CVE-2010-0917Windows VBScript 多个栈缓冲区错误漏洞
CVE-2010-0766Luxology Modo 401 'valet4.dll' 整数溢出漏洞
CVE-2009-4656E-Soft DJ Studio Pro 栈缓冲区溢出漏洞
CVE-2010-0156Puppet任意文件覆盖漏洞
CVE-2009-4664Firewall Builder不安全临时文件创建漏洞
CVE-2009-4663Quiksoft EasyMail Objects AddAttachment()方式缓冲区溢出漏洞
CVE-2009-4662Novell GroupWise WebAccess User.Theme.index参数跨站脚本漏洞
CVE-2009-4661BigAnt Server多个缓冲区溢出漏洞
CVE-2009-4660BigAnt IM HTTP GET请求栈溢出漏洞
CVE-2009-4659MP3-Cutter Ease Audio Cutter未明漏洞
CVE-2009-4658Omidrouhani Xerver拒绝服务漏洞

Showing top 20 of 22 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-0205

No comments yet


Leave a comment