CVE-2008-3964
Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the png_push_read_zTXt function in pngread.c, and possibly related to (2) pngtest.c.
- Affected products
- Libpng
- Libpng
- < 1.2.32, 1.4.0
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 3.3% (87th percentile)
- Weakness
- CWE-193
- NVD status
- Modified
- Published
- 2008-09-10
CVE-2008-3964 at NVD
No indexed exploits for CVE-2008-3964 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2008-3964 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.