CVE-2021-4214

SOURCE - nist

Summary

A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.

EPSS Score: 0.00051 (0.193)

Common Weakness Enumeration (CWE)

SOURCE - nist

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

SOURCE - gitlab

OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities

SOURCE - redhat

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/libpng1.6debdebian12>=1.6.39-2Not yet available
debian/libpng1.6debdebianunstable>=1.6.43-5Not yet available
debian/libpng1.6debdebian10>=1.6.36-6Not yet available
debian/libpng1.6debdebian13>=1.6.43-5Not yet available
debian/libpng1.6debdebian11>=1.6.37-3Not yet available

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

1.8


EXPLOITS FOUND

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

5.5medium

ubuntu

CREATED


UPDATED



EXPLOITABILITY SCORE

1.8


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

5.5medium

gitlab

CREATED


UPDATED


SOURCE ID

CVE-2021-4214


EXPLOITABILITY SCORE

1.8


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

5.5medium

redhat

CREATED


UPDATED



EXPLOITABILITY SCORE

1.8


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

5.5medium

inthewild

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND

-


COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE