CVE-2008-5907
Summary
| CVE | CVE-2008-5907 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-01-15 17:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The png_check_keyword function in pngwutil.c in libpng before 1.0.42, and 1.2.x before 1.2.34, might allow context-dependent attackers to set the value of an arbitrary memory location to zero via vectors involving creation of crafted PNG files with keywords, related to an implicit cast of the '\0' character constant to a NULL pointer. NOTE: some sources incorrectly report this as a double free vulnerability. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Debian -- Security Information -- DSA-1750-1 libpng | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| LIBPNG | af854a3a-2127-422b-91ae-364da2661108 | libpng.sourceforge.net | Third Party Advisory |
| Gentoo Linux Documentation -- libpng: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:003 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Third Party Advisory |
| Gentoo update for libpng - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Debian update for libpng - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| oss-security - libpng non issue | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Mailing List, Third Party Advisory |
| PNG and MNG/JNG image formats: home site / Thread: [png-mng-implement] Memory overwriting bug in png_check_keyword() | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-02-11 | Joshua Bressers | Red Hat does not consider this bug to be a security issue. For a more detailed explanation, please see the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-5907 |
There are currently no legacy QID mappings associated with this CVE.