The png_push_read_chunk function in pngpread.c in the progressive decoder in libpng 1.6.x through 1.6.9 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an IDAT chunk with a length of zero.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libpng1.6 | Jul 30, 2024 | Feb 27, 2014 |
| Gentoo Linux | — | Upgrade media-libs/libpng. | Oct 30, 2017 | Feb 27, 2014 |
| Suse | — | Upgrade libpng16-develUpgrade libpng16-16-32bitUpgrade libpng16-16Upgrade libpng16-compat-devel | Dec 18, 2015 | Feb 27, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub