HTTP: PNG IHDR-chunk Bad Parameter

This anomaly triggers if the PNG IHDR-chunk with the image parameters, such as Height or Width is too big, or Color-Type contains an invalid value. Note: An abnormally large non-malicious image can also trigger this anomaly.

Extended Description

The libpng graphics library is reported prone to multiple vulnerabilities. The following issues are reported: - A stack-based buffer-overrun vulnerability resides in the libpng library (CAN-2004-0597). A remote attacker may exploit this condition by supplying a malicious image to an unsuspecting user. When this image is viewed, the vulnerability may be triggered, resulting in code execution in the context of the user that viewed the malicious image. - A denial-of-service vulnerability affects libpng (CAN-2004-0598). A remote attacker may exploit this condition by supplying a malicious image to an unsuspecting user. When the malicious image is viewed, a NULL-pointer dereference will occur, resulting in a crash of the application that is linked to the vulnerable library. - Several integer-overrun vulnerabilities reside in png_handle_sPLT(), png_read_png(), and other functions of libpng (CAN-2004-0599). A remote attacker may exploit the integer-overrun issues by supplying a malicious image to an unsuspecting user. When the malicious image is viewed, an integer value may wrap or may be interpreted incorrectly, resulting in a crash of the application that is linked to the vulnerable library or possibly arbitrary code execution. This BID will be split into independent BIDs when further analysis of these issues is complete. ** Update: Microsoft MSN Messenger and Windows Messenger use an affected version of the libpng library and are therefore affected by this vulnerability. Reportedly, attackers can exploit this while sending images through supported functionality to unsuspecting users running the vulnerable software. Please see the Core Security Technologies Advisory for more information.

Affected Products

Mozilla browser

Short Name
HTTP:STC:IMG:PNG-IHDR-BAD-PAR
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2004-0597 CVE-2004-1244 CVE-2008-4064 CVE-2009-3126 IHDR PNG bid:10857 bid:36649
Release Date
11/07/2005
Supported Platforms

srx-branch-12.3

srx-branch-19.3

vsrx3bsd-19.2

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

srx-19.4

vsrx-12.3

srx-12.3

vsrx-19.2

srx-19.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Conectiva

Compaq

Trustix

Sun

Libpng

Nortel_networks

Imagemagick

Gentoo

Hp

Mozilla

Avaya

Graphicsmagick

Debian

Openpkg

Mandriva

Adobe

Microsoft

Red_hat

Sco

Suse

Apple

Turbolinux

Netscape

Sgi

CVSS Score

9.3

7.5

10.0

Found a potential security threat?