CVE-2013-6954
CVE-2013-6954
The png_do_expand_palette function in libpng before 1.6.8 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via (1) a PLTE chunk of zero bytes or (2) a NULL palette, related to pngrtran.c and pngset.c.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://advisories.mageia.org/MGASA-2014-0075.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-February/127947.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-February/127952.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-February/128098.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-February/128099.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-February/128114.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00071.htmlhttp://marc.info/?l=bugtraq&m=140852886808946&w=2http://marc.info/?l=bugtraq&m=140852974709252&w=2https://access.redhat.com/errata/RHSA-2014:0413https://access.redhat.com/errata/RHSA-2014:0414https://bugzilla.redhat.com/show_bug.cgi?id=1045561