CVE Vulnerabilities

CVE-2013-6954

Published: Jan 12, 2014 | Modified: Jan 05, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The png_do_expand_palette function in libpng before 1.6.8 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via (1) a PLTE chunk of zero bytes or (2) a NULL palette, related to pngrtran.c and pngset.c.

Affected Software

Name Vendor Start Version End Version
Libpng Libpng 1.6.0 1.6.0
Libpng Libpng 1.6.1 1.6.1
Libpng Libpng 1.6.3 1.6.3
Libpng Libpng 1.6.0 1.6.0
Libpng Libpng 1.6.4 1.6.4
Libpng Libpng 1.6.7 1.6.7
Libpng Libpng 1.6.1 1.6.1
Libpng Libpng 1.6.6 1.6.6
Libpng Libpng 1.6.7 1.6.7
Libpng Libpng * 1.6.8
Libpng Libpng 1.6.4 1.6.4
Libpng Libpng 1.6.3 1.6.3
Libpng Libpng 1.6.2 1.6.2
Libpng Libpng 1.6.2 1.6.2
Libpng Libpng 1.6.5 1.6.5

References