DEBIAN-CVE-2005-2978

Source
https://security-tracker.debian.org/tracker/CVE-2005-2978
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2005-2978.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2005-2978
Upstream
Downstream
Published
2005-10-18T22:02:00Z
Modified
2025-11-19T02:04:41.818245Z
Summary
[none]
Details

pnmtopng in netpbm before 10.25, when using the -trans option, uses uninitialized size and index variables when converting Portable Anymap (PNM) images to Portable Network Graphics (PNG), which might allow attackers to execute arbitrary code by modifying the stack.

References

Affected packages

Debian:11 / netpbm-free

Package

Name
netpbm-free
Purl
pkg:deb/debian/netpbm-free?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:10.0-10

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2005-2978.json"

Debian:12 / netpbm-free

Package

Name
netpbm-free
Purl
pkg:deb/debian/netpbm-free?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:10.0-10

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2005-2978.json"

Debian:13 / netpbm-free

Package

Name
netpbm-free
Purl
pkg:deb/debian/netpbm-free?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:10.0-10

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2005-2978.json"

Debian:14 / netpbm-free

Package

Name
netpbm-free
Purl
pkg:deb/debian/netpbm-free?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:10.0-10

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2005-2978.json"