Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-2445

16
FAUCET Score

CVE-2007-2445 describes a denial-of-service vulnerability in the png_handle_tRNS function of libpng versions prior to 1.0.25 and 1.2.17, affecting products like Linux and the png_reference_library. An unauthenticated remote attacker can trigger an application crash by providing a specially crafted grayscale PNG image with an invalid tRNS chunk CRC value. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P), this vulnerability is easily exploitable over the network with low attack complexity, leading to a partial availability impact. There is no evidence of active exploitation, nor are public exploit modules available in Metasploit, Nuclei, or ExploitDB, and it has garnered minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.0.15CPE matchmatch criteria
cpe:2.3:a:png_reference_library:libpng:*:*:*:*:*:*:*:*
<= 1.2.16CPE matchmatch criteria
cpe:2.3:a:png_reference_library:libpng:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
5.12%
Probability of exploitation in next 30 days
EPSS Percentile
91.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0512 is in the 88th percentile among its peer group of 23,701 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: libpng-2:1.0.14-10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: libpng-2:1.2.2-27
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: libpng10-0:1.0.13-17
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: libpng-2:1.2.7-3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: libpng10-0:1.0.16-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: libpng-2:1.2.10-7.0.2
View patch

Vendor Advisories (1)

redhatCVE-2007-2445Moderate

libpng png_handle_tRNS flaw

May 15, 2007

References

android-developers.blogspot.com / 2008/03/android-sdk-update-m5-rc15-released.html
docs.info.apple.com / article.html
irrlicht.sourceforge.net / changes.txt
lists.apple.com / archives/security-announce/2008/Mar/msg00001.html
openpkg.com / go/OpenPKG-SA-2007.013
osvdb.org / 36196
secunia.com / advisories/25268
Vendor Advisory
secunia.com / advisories/25273
Vendor Advisory
secunia.com / advisories/25292
Vendor Advisory
secunia.com / advisories/25329
Vendor Advisory
secunia.com / advisories/25353
secunia.com / advisories/25461
secunia.com / advisories/25554
secunia.com / advisories/25571
secunia.com / advisories/25742
secunia.com / advisories/25787
secunia.com / advisories/25867
secunia.com / advisories/27056
secunia.com / advisories/29420
secunia.com / advisories/30161
secunia.com / advisories/31168
secunia.com / advisories/34388
exchange.xforce.ibmcloud.com / vulnerabilities/34340
issues.rpath.com / browse/RPL-1381
slackware.com / security/viewer.php
sourceforge.net / project/shownotes.php
Patch
sourceforge.net / project/shownotes.php
Patch
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10094
sunsolve.sun.com / search/document.do
sunsolve.sun.com / search/document.do
support.avaya.com / elmodocs2/security/ASA-2007-254.htm
coresecurity.com
debian.org / security/2008/dsa-1613
debian.org / security/2009/dsa-1750
gentoo.org / security/en/glsa/glsa-200705-24.xml
gentoo.org / security/en/glsa/glsa-200805-07.xml
kb.cert.org / vuls/id/684664
Third Party AdvisoryUS Government Resource
mandriva.com / security/advisories
mirrorservice.org / sites/download.sourceforge.net/pub/sourceforge/l/li/libpng/libpng-1.2.17-ADVISORY.txt
Vendor Advisory
novell.com / linux/security/advisories/2007_13_sr.html
redhat.com / support/errata/RHSA-2007-0356.html
securityfocus.com / archive/1/468910/100/0/threaded
securityfocus.com / archive/1/489135/100/0/threaded
securityfocus.com / bid/24000
securityfocus.com / bid/24023
securitytracker.com / id
trustix.org / errata/2007/0019
ubuntu.com / usn/usn-472-1
vupen.com / english/advisories/2007/1838
vupen.com / english/advisories/2007/2385
vupen.com / english/advisories/2008/0924/references