Vulnerability record · CVE-2004-0597 · published 23 November 2004
CVE-2004-0597: libpng PNG chunk buffer overflows allow remote code execution
Greg Roelofs · Libpng
libpng 1.2.5 and earlier contain multiple buffer overflows in the png_handle_tRNS, png_handle_sBIT and png_handle_hIST functions, which fail to validate chunk lengths or perform sufficient bounds checking. Because libpng is embedded in many products, a malformed PNG image can crash or compromise any application that decodes it. The flaw matters because image parsing is a common, often automatic, path into a host.
Description
Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with no authentication and a very high EPSS score, though the record is old and exploitation requires a crafted image to be opened.
What it is
libpng 1.2.5 and earlier contain multiple buffer overflows in the png_handle_tRNS, png_handle_sBIT and png_handle_hIST functions, which fail to validate chunk lengths or perform sufficient bounds checking. Because libpng is embedded in many products, a malformed PNG image can crash or compromise any application that decodes it. The flaw matters because image parsing is a common, often automatic, path into a host.
Impact
An attacker can execute arbitrary code in the context of the process that decodes the PNG, or at minimum cause a denial of service. On desktop and server software that renders untrusted images, this can lead to full host compromise.
Attack surface
Reached remotely by supplying a crafted PNG image to any libpng-based decoder, including browsers, media players and messaging clients. No authentication is required, but the victim or an automated process must open or render the image, so some user interaction or file processing is needed.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.825, 99.6th percentile) and a reference is tagged Exploit, indicating public exploit code exists. No ransomware group is documented as using it.
What to do
- Upgrade libpng to a version later than 1.2.5, or apply the vendor patch for each affected product.
- Patch or replace bundled libpng copies in applications such as media players, messaging clients and browsers, since they may not track the system library.
- Block or strip untrusted PNG attachments and inline images at mail and web gateways where feasible.
- Run image-decoding services and desktop applications with least privilege to limit the impact of code execution.
Detection
- Monitor for crashes or abnormal termination in processes that decode PNG files, especially repeated failures on the same file.
- Inspect PNG files for malformed tRNS, sBIT or hIST chunks with lengths inconsistent with the image header.
- Watch for unexpected child processes or network connections spawned by image viewers, browsers or media players.
- Use file integrity monitoring on libpng libraries and dependent applications to catch unpatched or replaced versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0597 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0597), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.