Description
libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.
Published: 2009-06-12
Score: 4.3 Medium
EPSS: 3.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-2032-1 New libpng packages fix several vulnerabilities
EUVD EUVD EUVD-2009-2038 libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.
Ubuntu USN Ubuntu USN USN-913-1 libpng vulnerabilities
References
Link Providers
http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html cve-icon cve-icon
http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html cve-icon cve-icon
http://lists.vmware.com/pipermail/security-announce/2010/000090.html cve-icon cve-icon
http://secunia.com/advisories/35346 cve-icon cve-icon
http://secunia.com/advisories/35470 cve-icon cve-icon
http://secunia.com/advisories/35524 cve-icon cve-icon
http://secunia.com/advisories/35594 cve-icon cve-icon
http://secunia.com/advisories/39206 cve-icon cve-icon
http://secunia.com/advisories/39215 cve-icon cve-icon
http://secunia.com/advisories/39251 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200906-01.xml cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.551809 cve-icon cve-icon
http://support.apple.com/kb/HT4077 cve-icon cve-icon
http://ubuntu.com/usn/usn-913-1 cve-icon cve-icon
http://www.debian.org/security/2010/dsa-2032 cve-icon cve-icon
http://www.libpng.org/pub/png/libpng.html cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2010:063 cve-icon cve-icon
http://www.securityfocus.com/bid/35233 cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2010-0007.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/1510 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/0637 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/0682 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/0847 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/50966 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2009-2042 cve-icon
https://www.cve.org/CVERecord?id=CVE-2009-2042 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00218.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00630.html cve-icon cve-icon
History

No history.

Subscriptions

Libpng Libpng
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T05:36:20.484Z

Reserved: 2009-06-12T00:00:00.000Z

Link: CVE-2009-2042

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2009-06-12T20:30:00.203

Modified: 2026-04-23T00:35:47.467

Link: CVE-2009-2042

cve-icon Redhat

Severity : Low

Publid Date: 2009-06-04T00:00:00Z

Links: CVE-2009-2042 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses