Medium severity6.5NVD Advisory· Published Jun 30, 2010· Updated Apr 29, 2026
CVE-2010-2249
CVE-2010-2249
Description
Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.
Affected products
21cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*+ 4 more
- cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:12:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:12:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:13:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:10:sp3:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:suse:linux_enterprise_server:10:sp3:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise_server:11:-:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
40- slackware.com/security/viewer.phpnvdMailing ListPatchThird Party Advisory
- www.securityfocus.com/bid/41174nvdPatchThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlnvdMailing ListThird Party Advisory
- lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlnvdMailing ListThird Party Advisory
- lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlnvdMailing ListThird Party Advisory
- lists.apple.com/archives/security-announce/2011/Mar/msg00000.htmlnvdMailing ListThird Party Advisory
- lists.fedoraproject.org/pipermail/package-announce/2010-July/044283.htmlnvdMailing ListThird Party Advisory
- lists.fedoraproject.org/pipermail/package-announce/2010-July/044397.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlnvdMailing ListThird Party Advisory
- lists.vmware.com/pipermail/security-announce/2010/000105.htmlnvdMailing ListThird Party Advisory
- support.apple.com/kb/HT4456nvdThird Party Advisory
- support.apple.com/kb/HT4457nvdThird Party Advisory
- support.apple.com/kb/HT4554nvdThird Party Advisory
- www.debian.org/security/2010/dsa-2072nvdThird Party Advisory
- www.libpng.org/pub/png/libpng.htmlnvdProductVendor Advisory
- www.securitytracker.com/idnvdThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/USN-960-1nvdThird Party Advisory
- www.vmware.com/security/advisories/VMSA-2010-0014.htmlnvdThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/59816nvdThird Party AdvisoryVDB Entry
- secunia.com/advisories/40302nvdBroken Link
- secunia.com/advisories/40336nvdBroken Link
- secunia.com/advisories/40472nvdBroken Link
- secunia.com/advisories/40547nvdBroken Link
- secunia.com/advisories/41574nvdBroken Link
- secunia.com/advisories/42314nvdBroken Link
- secunia.com/advisories/42317nvdBroken Link
- support.apple.com/kb/HT4435nvdBroken Link
- support.apple.com/kb/HT4566nvdBroken Link
- www.mandriva.com/security/advisoriesnvdBroken Link
- www.vupen.com/english/advisories/2010/1612nvdBroken Link
- www.vupen.com/english/advisories/2010/1637nvdBroken Link
- www.vupen.com/english/advisories/2010/1755nvdBroken Link
- www.vupen.com/english/advisories/2010/1837nvdBroken Link
- www.vupen.com/english/advisories/2010/1846nvdBroken Link
- www.vupen.com/english/advisories/2010/1877nvdBroken Link
- www.vupen.com/english/advisories/2010/2491nvdBroken Link
- www.vupen.com/english/advisories/2010/3045nvdBroken Link
- www.vupen.com/english/advisories/2010/3046nvdBroken Link
- libpng.git.sourceforge.net/git/gitweb.cginvd
News mentions
0No linked articles in our index yet.