← Vulnerability feed

Vulnerability record · CVE-2004-0597 · published 23 November 2004

CVE-2004-0597: libpng PNG chunk buffer overflows allow remote code execution

Greg Roelofs · Libpng

libpng 1.2.5 and earlier contain multiple buffer overflows in the png_handle_tRNS, png_handle_sBIT and png_handle_hIST functions, which fail to validate chunk lengths or perform sufficient bounds checking. Because libpng is embedded in many products, a malformed PNG image can crash or compromise any application that decodes it. The flaw matters because image parsing is a common, often automatic, path into a host.

10.0 CVSS 2.0 High EPSS 83% · top 0.3%
10.0CVSS 2.0 base score
83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
84References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote code execution with no authentication and a very high EPSS score, though the record is old and exploitation requires a crafted image to be opened.

What it is

libpng 1.2.5 and earlier contain multiple buffer overflows in the png_handle_tRNS, png_handle_sBIT and png_handle_hIST functions, which fail to validate chunk lengths or perform sufficient bounds checking. Because libpng is embedded in many products, a malformed PNG image can crash or compromise any application that decodes it. The flaw matters because image parsing is a common, often automatic, path into a host.

Impact

An attacker can execute arbitrary code in the context of the process that decodes the PNG, or at minimum cause a denial of service. On desktop and server software that renders untrusted images, this can lead to full host compromise.

Attack surface

Reached remotely by supplying a crafted PNG image to any libpng-based decoder, including browsers, media players and messaging clients. No authentication is required, but the victim or an automated process must open or render the image, so some user interaction or file processing is needed.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.825, 99.6th percentile) and a reference is tagged Exploit, indicating public exploit code exists. No ransomware group is documented as using it.

What to do

  • Upgrade libpng to a version later than 1.2.5, or apply the vendor patch for each affected product.
  • Patch or replace bundled libpng copies in applications such as media players, messaging clients and browsers, since they may not track the system library.
  • Block or strip untrusted PNG attachments and inline images at mail and web gateways where feasible.
  • Run image-decoding services and desktop applications with least privilege to limit the impact of code execution.

Detection

  • Monitor for crashes or abnormal termination in processes that decode PNG files, especially repeated failures on the same file.
  • Inspect PNG files for malformed tRNS, sBIT or hIST chunks with lengths inconsistent with the image header.
  • Watch for unexpected child processes or network connections spawned by image viewers, browsers or media players.
  • Use file integrity monitoring on libpng libraries and dependent applications to catch unpatched or replaced versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000856
http://lists.apple.com/mhonarc/security-announce/msg00056.html
http://marc.info/?l=bugtraq&m=109163866717909&w=2
http://marc.info/?l=bugtraq&m=109181639602978&w=2
http://marc.info/?l=bugtraq&m=109761239318458&w=2
http://marc.info/?l=bugtraq&m=109900315219363&w=2
http://marc.info/?l=bugtraq&m=110796779903455&w=2
http://scary.beasts.org/security/CESA-2004-001.txt ExploitVendor Advisory
http://secunia.com/advisories/22957
http://secunia.com/advisories/22958
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200663-1
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-114816-02-1
http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679 Patch
http://www.coresecurity.com/common/showdoc.php?idx=421&idxseccion=10
http://www.debian.org/security/2004/dsa-536 PatchVendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200408-03.xml PatchVendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200408-22.xml PatchVendor Advisory
http://www.kb.cert.org/vuls/id/388984 Third Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/817368 Third Party AdvisoryUS Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2004:079
http://www.mandriva.com/security/advisories?name=MDKSA-2006:212
http://www.mandriva.com/security/advisories?name=MDKSA-2006:213
http://www.mozilla.org/projects/security/known-vulnerabilities.html
http://www.novell.com/linux/security/advisories/2004_23_libpng.html PatchVendor Advisory
http://www.redhat.com/support/errata/RHSA-2004-402.html
http://www.redhat.com/support/errata/RHSA-2004-421.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2004-429.html Vendor Advisory
http://www.securityfocus.com/bid/10857 ExploitPatchVendor Advisory
http://www.securityfocus.com/bid/15495
http://www.trustix.net/errata/2004/0040/ PatchVendor Advisory
http://www.us-cert.gov/cas/techalerts/TA04-217A.html Third Party AdvisoryUS Government Resource
http://www.us-cert.gov/cas/techalerts/TA05-039A.html Third Party AdvisoryUS Government Resource
https://bugzilla.fedora.us/show_bug.cgi?id=1943
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-009
https://exchange.xforce.ibmcloud.com/vulnerabilities/16894
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11284
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2274
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2378
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4492

Track CVE-2004-0597 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3009Microsoft windows media player vulnerabilityMicrosoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the …EPSS 16%10.0CVE-2008-3010Microsoft windows media player information exposure vulnerabilityMicrosoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1 and 9 incorrectly associate ISATAP ad…EPSS 15%10.0CVE-2005-0059Microsoft Windows Message Queuing buffer overflow allows remote code executionThe Message Queuing component in Microsoft Windows 2000 and Windows XP SP1 contains a buffer overflow that can be triggered by a crafted message. A r…EPSS 73%analysed10.0CVE-2004-0571Microsoft windows 2000 vulnerabilityMicrosoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via…EPSS 31%10.0CVE-2004-0901Microsoft windows 2000 vulnerabilityMicrosoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote att…EPSS 32%10.0CVE-2004-0214Microsoft Internet Explorer and Explorer share name buffer overflowA buffer overflow exists in Microsoft Internet Explorer and Windows Explorer on Windows XP SP1, 2000, 98, and Me when handling long share names, as d…EPSS 47%analysed10.0CVE-2004-0201Microsoft HTML Help hh.exe heap buffer overflow via crafted CHM fileThe HTML Help program (hh.exe) in multiple Microsoft Windows versions contains a heap-based buffer overflow triggered by a .CHM file with a large len…EPSS 45%analysed10.0CVE-2002-1257Microsoft windows 2000 vulnerabilityMicrosoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that i…EPSS 15%

Source: NIST National Vulnerability Database (record CVE-2004-0597), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.