CVE-2013-6954

The png_do_expand_palette function in libpng before 1.6.8 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via (1) a PLTE chunk of zero bytes or (2) a NULL palette, related to pngrtran.c and pngset.c.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
libpnglibpng
𝑥
≤ 1.6.8
libpnglibpng
1.6.0
libpnglibpng
1.6.0:beta
libpnglibpng
1.6.1
libpnglibpng
1.6.1:beta
libpnglibpng
1.6.2
libpnglibpng
1.6.2:beta
libpnglibpng
1.6.3
libpnglibpng
1.6.3:beta
libpnglibpng
1.6.4
libpnglibpng
1.6.4:beta
libpnglibpng
1.6.5
libpnglibpng
1.6.6
libpnglibpng
1.6.7
libpnglibpng
1.6.7:beta
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libpng
lucid
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
openjdk-7
lucid
dne
precise
ignored
quantal
ignored
saucy
ignored
trusty
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
java-1_7_0-openjdk
suse enterprise sap 12 SP5
1.7.0.231-43.27.2
fixed
suse enterprise server 12 SP5
1.7.0.231-43.27.2
fixed
java-1_7_0-openjdk-demo
suse enterprise sap 12 SP5
1.7.0.231-43.27.2
fixed
suse enterprise server 12 SP5
1.7.0.231-43.27.2
fixed
java-1_7_0-openjdk-devel
suse enterprise sap 12 SP5
1.7.0.231-43.27.2
fixed
suse enterprise server 12 SP5
1.7.0.231-43.27.2
fixed
java-1_7_0-openjdk-headless
suse enterprise sap 12 SP5
1.7.0.231-43.27.2
fixed
suse enterprise server 12 SP5
1.7.0.231-43.27.2
fixed
libpng16-16
suse enterprise sap 12 SP5
1.6.8-14.1
fixed
suse enterprise server 12 SP5
1.6.8-14.1
fixed
libpng16-16-32bit
suse enterprise sap 12 SP5
1.6.8-14.1
fixed
suse enterprise server 12 SP5
1.6.8-14.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
java-1.6.0-ibm
RHEL 6
1:1.6.0.16.0-1jpp.1.el6_5
fixed
java-1.6.0-ibm-demo
RHEL 6
1:1.6.0.16.0-1jpp.1.el6_5
fixed
java-1.6.0-ibm-devel
RHEL 6
1:1.6.0.16.0-1jpp.1.el6_5
fixed
java-1.6.0-ibm-javacomm
RHEL 6
1:1.6.0.16.0-1jpp.1.el6_5
fixed
java-1.6.0-ibm-jdbc
RHEL 6
1:1.6.0.16.0-1jpp.1.el6_5
fixed
java-1.6.0-ibm-plugin
RHEL 6
1:1.6.0.16.0-1jpp.1.el6_5
fixed
java-1.6.0-ibm-src
RHEL 6
1:1.6.0.16.0-1jpp.1.el6_5
fixed
java-1.7.0-ibm
RHEL 6
1:1.7.0.7.0-1jpp.1.el6_5
fixed
java-1.7.0-ibm-demo
RHEL 6
1:1.7.0.7.0-1jpp.1.el6_5
fixed
java-1.7.0-ibm-devel
RHEL 6
1:1.7.0.7.0-1jpp.1.el6_5
fixed
java-1.7.0-ibm-jdbc
RHEL 6
1:1.7.0.7.0-1jpp.1.el6_5
fixed
java-1.7.0-ibm-plugin
RHEL 6
1:1.7.0.7.0-1jpp.1.el6_5
fixed
java-1.7.0-ibm-src
RHEL 6
1:1.7.0.7.0-1jpp.1.el6_5
fixed
java-1.7.0-oracle
RHEL 6
1:1.7.0.55-1jpp.1.el6_5
fixed
java-1.7.0-oracle-devel
RHEL 6
1:1.7.0.55-1jpp.1.el6_5
fixed
java-1.7.0-oracle-javafx
RHEL 6
1:1.7.0.55-1jpp.1.el6_5
fixed
java-1.7.0-oracle-jdbc
RHEL 6
1:1.7.0.55-1jpp.1.el6_5
fixed
java-1.7.0-oracle-plugin
RHEL 6
1:1.7.0.55-1jpp.1.el6_5
fixed
java-1.7.0-oracle-src
RHEL 6
1:1.7.0.55-1jpp.1.el6_5
fixed
java-1.7.1-ibm
RHEL 7
1:1.7.1.1.0-1jpp.2.el7_0
fixed
java-1.7.1-ibm-demo
RHEL 7
1:1.7.1.1.0-1jpp.2.el7_0
fixed
java-1.7.1-ibm-devel
RHEL 7
1:1.7.1.1.0-1jpp.2.el7_0
fixed
java-1.7.1-ibm-jdbc
RHEL 7
1:1.7.1.1.0-1jpp.2.el7_0
fixed
java-1.7.1-ibm-plugin
RHEL 7
1:1.7.1.1.0-1jpp.2.el7_0
fixed
java-1.7.1-ibm-src
RHEL 7
1:1.7.1.1.0-1jpp.2.el7_0
fixed
References