Vulnerability Note VU#650142

libpng 1.6.1 through 1.6.7 contain a null-pointer dereference vulnerability

Original Release date: 09 Jan 2014 | Last revised: 09 Jan 2014

Overview

libpng versions 1.6.1 through 1.6.7 fail to reject colormapped images with empty palettes, leading to a null-pointer dereference (crash) in png_do_expand_palette().

Description

The PNG Development Group has reported that "libpng versions 1.6.1 through 1.6.7 fail to reject colormapped images with empty palettes, leading to a null-pointer dereference (crash) in png_do_expand_palette()".

Impact

An attacker may be able to exploit an application that uses libpng to execute arbitrary code or cause a denial-of-service.

Solution

Apply an Update

libpng 1.6.8 has addressed this vulnerability.

Vendor Information (Learn More)

VendorStatusDate NotifiedDate Updated
libpngAffected-09 Jan 2014
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

Group Score Vector
Base 3.3 AV:L/AC:M/Au:N/C:P/I:P/A:N
Temporal 2.4 E:U/RL:OF/RC:C
Environmental 2.5 CDP:ND/TD:H/CR:ND/IR:ND/AR:ND

References

Credit

Thanks to Glenn Randers-Pehrson for reporting this vulnerability.

This document was written by Jared Allar.

Other Information

  • CVE IDs: CVE-2013-6954
  • Date Public: 19 Dec 2013
  • Date First Published: 09 Jan 2014
  • Date Last Updated: 09 Jan 2014
  • Document Revision: 4

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.