CVE-2004-0599

Publication date 23 November 2004

Last updated 17 July 2025


Ubuntu priority

Description

Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.

Status

Package Ubuntu Release Status
libpng 7.04 feisty
Fixed 1.2.15~beta5-1ubuntu1
6.10 edgy
Fixed 1.2.8rel-5.1ubuntu0.2
6.06 LTS dapper
Fixed 1.2.8rel-5ubuntu0.2
libpng3 7.04 feisty Not in release
6.10 edgy
Fixed 1.2.8rel-1ubuntu3
6.06 LTS dapper
Fixed 1.2.8rel-1ubuntu3