Summary
The remote host is probably affected by the vulnerabilities described in CVE-2008-1382
Impact
libpng 1.0.6 through 1.0.32, 1.2.0 through 1.2.26, and 1.4.0beta01 through 1.4.0beta19 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PNG file with zero length unknown chunks, which trigger an access of uninitialized memory.
Solution
All users should upgrade to the latest libpng version of their Linux Distribution.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2008-1382 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Adobe AIR Multiple Vulnerabilities-01 Jun14 (Windows)
- Adobe Flash Player Arbitrary Code Execution Vulnerability - 01 Feb14 (Windows)
- Adobe AIR Multiple Vulnerabilities-01 Jan15 (Windows)
- Adobe Flash Player 9.0.115.0 and earlier vulnerability (Lin)
- Adobe Acrobat Multiple Vulnerabilities -01 Jan 13 (Mac OS X)