PT-2014-1614 · Libpng+5 · Libpng+5

Vincent Danen

·

Published

2014-01-12

·

Updated

2025-06-10

·

CVE-2013-6954

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libpng versions prior to 1.6.8
Description The issue allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and application crash. This can be achieved via a PLTE chunk of zero bytes or a NULL palette, and is related to the pngrtran.c and pngset.c files.
Recommendations For libpng versions prior to 1.6.8, update to version 1.6.8 or later to resolve the issue. As a temporary workaround, consider restricting the use of the png do expand palette function to minimize the risk of exploitation.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00532
CVE-2013-6954
DSA-2923-1
HPSBUX03091
HPSBUX03092
MGASA-2014-0075
MGASA-2014-0076
OPENSUSE-SU-2024:10050-1
OPENSUSE-SU-2024:10534-1
RHSA-2014:0412
RHSA-2014:0413
RHSA-2014:0414
RHSA-2014:0486
RHSA-2014:0508
RHSA-2014:0705
RHSA-2014:0982
RHSA-2014_0412
RHSA-2014_0413
RHSA-2014_0414
RHSA-2014_0486
RHSA-2014_0508
RHSA-2014_0705

Affected Products

Hp-Ux
Ibm Aix
Java Platform
Red Hat
Suse
Libpng