CVE-2004-0597 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 82.5% (pctl 100)
Patch early
A public exploit exists.
Description
Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 82.54% — more likely to be exploited than 100% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-11-23 |
| Last modified | 2026-06-16 |
Affected (6)
| Vendor | Product |
|---|---|
| greg roelofs | libpng |
| microsoft | msn messenger |
| microsoft | windows 98se |
| microsoft | windows me |
| microsoft | windows media player |
| microsoft | windows messenger |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft MSN Messenger 6.2.0137 - '.png' Remote Buffer Overflow | 2005-02-08 |
| exploit-db | LibPNG 1.2.5 - 'png_jmpbuf()' Local Buffer Overflow | 2004-08-13 |
| exploit-db | LibPNG Graphics Library - Remote Buffer Overflow | 2004-08-11 |
References
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000856
- http://lists.apple.com/mhonarc/security-announce/msg00056.html
- http://marc.info/?l=bugtraq&m=109163866717909&w=2
- http://marc.info/?l=bugtraq&m=109181639602978&w=2
- http://marc.info/?l=bugtraq&m=109761239318458&w=2
- http://marc.info/?l=bugtraq&m=109900315219363&w=2
- http://marc.info/?l=bugtraq&m=110796779903455&w=2
- http://scary.beasts.org/security/CESA-2004-001.txt
- http://secunia.com/advisories/22957
- http://secunia.com/advisories/22958
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-200663-1
- http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-114816-02-1
- http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679
- http://www.coresecurity.com/common/showdoc.php?idx=421&idxseccion=10
- http://www.debian.org/security/2004/dsa-536
- http://www.gentoo.org/security/en/glsa/glsa-200408-03.xml
- http://www.gentoo.org/security/en/glsa/glsa-200408-22.xml
- http://www.kb.cert.org/vuls/id/388984
- http://www.kb.cert.org/vuls/id/817368
→ the Explorer · watch your stack · NVD