Lucene search

K
certCERTVU:650142
HistoryJan 09, 2014 - 12:00 a.m.

libpng 1.6.1 through 1.6.7 contain a null-pointer dereference vulnerability

2014-01-0900:00:00
www.kb.cert.org
25

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.133

Percentile

95.6%

Overview

libpng versions 1.6.1 through 1.6.7 fail to reject colormapped images with empty palettes, leading to a null-pointer dereference (crash) in png_do_expand_palette().

Description

The PNG Development Group has reported that “libpng versions 1.6.1 through 1.6.7 fail to reject colormapped images with empty palettes, leading to a null-pointer dereference (crash) in png_do_expand_palette()”.


Impact

An attacker may be able to exploit an application that uses libpng to execute arbitrary code or cause a denial-of-service.


Solution

Apply an Update

libpng 1.6.8 has addressed this vulnerability.


Vendor Information

650142

Filter by status: All Affected Not Affected Unknown

Filter by content: __ Additional information available

__ Sort by: Status Alphabetical

Expand all

Javascript is disabled. Click here to view vendors.

libpng Affected

Updated: January 09, 2014

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

CVSS Metrics

Group Score Vector
Base 3.3 AV:L/AC:M/Au:N/C:P/I:P/A:N
Temporal 2.4 E:U/RL:OF/RC:C
Environmental 2.5 CDP:ND/TD:H/CR:ND/IR:ND/AR:ND

References

<http://www.libpng.org/pub/png/libpng.html&gt;

Acknowledgements

Thanks to Glenn Randers-Pehrson for reporting this vulnerability.

This document was written by Jared Allar.

Other Information

CVE IDs: CVE-2013-6954
Date Public: 2013-12-19 Date First Published:

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.133

Percentile

95.6%