5
CVSSv2

CVE-2014-0333

Published: 27/02/2014 Updated: 26/03/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The png_push_read_chunk function in pngpread.c in the progressive decoder in libpng 1.6.x up to and including 1.6.9 allows remote malicious users to cause a denial of service (infinite loop and CPU consumption) via an IDAT chunk with a length of zero.

Vulnerable Product Search on Vulmon Subscribe to Product

libpng libpng 1.6.3

libpng libpng 1.6.4

libpng libpng 1.6.8

libpng libpng 1.6.9

libpng libpng 1.6.1

libpng libpng 1.6.6

libpng libpng 1.6.7

libpng libpng 1.6.2

libpng libpng 1.6.0

libpng libpng 1.6.5

Vendor Advisories

The png_push_read_chunk function in pngpreadc in the progressive decoder in libpng 16x through 169 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an IDAT chunk with a length of zero ...