CVE-2013-7354

Multiple integer overflows in libpng before 1.5.14rc03 allow remote attackers to cause a denial of service (crash) via a crafted image to the (1) png_set_sPLT or (2) png_set_text_2 function, which triggers a heap-based buffer overflow.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.0:beta:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.1:beta:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.2:beta:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.3:beta:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.4:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.4:beta:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.5:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.5:beta:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.6:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.6:beta:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.7:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.7:beta:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.8:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.8:beta:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.9:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.9:beta:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.10:beta:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.11:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.11:beta:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.12:*:*:*:*:*:*:*
cpe:2.3:a:libpng:libpng:1.5.13:beta:*:*:*:*:*:*

History

21 Nov 2024, 02:00

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-updates/2014-05/msg00015.html - () http://lists.opensuse.org/opensuse-updates/2014-05/msg00015.html -
References () http://seclists.org/oss-sec/2014/q2/83 - () http://seclists.org/oss-sec/2014/q2/83 -
References () http://sourceforge.net/p/libpng/bugs/199/ - Vendor Advisory () http://sourceforge.net/p/libpng/bugs/199/ - Vendor Advisory
References () http://www.securityfocus.com/bid/67344 - () http://www.securityfocus.com/bid/67344 -

Information

Published : 2014-05-06 14:55

Updated : 2024-11-21 02:00


NVD link : CVE-2013-7354

Mitre link : CVE-2013-7354

CVE.ORG link : CVE-2013-7354


JSON object : View

Products Affected

libpng

  • libpng
CWE
CWE-189

Numeric Errors