CVE-2011-3045 is an integer signedness error in the libpng library (versions prior to 1.4.10beta01), specifically within the png_inflate function in pngrutil.c. This flaw affects products like Google Chrome (before 17.0.963.83), Debian, Fedora, and OpenSUSE, allowing remote attackers to trigger a denial of service or potentially execute arbitrary code via a crafted PNG file. With a CVSS score of 8.8 (High), it presents a significant risk due to its network-based attack vector and low attack complexity, potentially leading to high impact on confidentiality, integrity, and availability. Despite its high severity, there is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.0.963.83CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:redhat:gluster_storage:2.0:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:redhat:storage:2.0:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:redhat:storage_for_public_cloud:2.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
libpng: buffer overflow in png_inflate caused by invalid type conversions
Mar 8, 2012Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.
Mar 2, 2012