Back to Database
Status published
High
CVE-2004-0768
libpng 1.2.5 and earlier does not properly calculate certain buffer...
Vulnerability Description
libpng 1.2.5 and earlier does not properly calculate certain buffer offsets, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-0768
Credits & Attribution
No credits recorded in the NVD database.
References
More from greg roelofs
View All →CVE-2011-3328
The png_handle_cHRM function in pngrutil.c in libpng 1.5.4, when color-correction...
Low
2.6
CVE-2006-5793
The sPLT chunk handling code (png_set_sPLT function in pngset.c) in...
Low
2.6
CVE-2006-3334
Buffer overflow in the png_decompress_chunk function in pngrutil.c in libpng...
High
7.5
CVE-2006-0481
Heap-based buffer overflow in the alpha strip capability in libpng...
Medium
5
CVE-2005-3662
Off-by-one buffer overflow in pnmtopng before 2.39, when using the...
Medium
4.6
Affected Vendor
greg roelofs
View all reports →Affected Software
libpng3
Vulnerable Versions:
1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5
Timeline
Official Publish:
August 19th, 2004
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.