// For flags

CVE-2014-0333

Gentoo Linux Security Advisory 201408-06

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The png_push_read_chunk function in pngpread.c in the progressive decoder in libpng 1.6.x through 1.6.9 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an IDAT chunk with a length of zero.

La función png_push_read_chunk en pngpread.c en el decodificador progresivo en libpng 1.6.x hasta 1.6.9 permite a atacantes remotos causar una denegación de servicio (bucle infinito y consumo de CPU) a través de un fragmento IDAT con una longitud cero.

The png_push_read_chunk function in pngpread.c in the progressive decoder in libpng 1.6.x through 1.6.9 allows remote attackers to cause a denial of service via an IDAT chunk with a length of zero. libpng versions 1.6.9 through 1.6.15 have an integer-overflow vulnerability in png_combine_row() when decoding very wide interlaced images, which can allow an attacker to overwrite an arbitrary amount of memory with arbitrary data.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-12-05 CVE Reserved
  • 2014-02-27 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-189: Numeric Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.0
Search vendor "Libpng" for product "Libpng" and version "1.6.0"
-
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.0
Search vendor "Libpng" for product "Libpng" and version "1.6.0"
beta
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.1
Search vendor "Libpng" for product "Libpng" and version "1.6.1"
-
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.1
Search vendor "Libpng" for product "Libpng" and version "1.6.1"
beta
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.2
Search vendor "Libpng" for product "Libpng" and version "1.6.2"
-
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.2
Search vendor "Libpng" for product "Libpng" and version "1.6.2"
beta
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.3
Search vendor "Libpng" for product "Libpng" and version "1.6.3"
-
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.3
Search vendor "Libpng" for product "Libpng" and version "1.6.3"
beta
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.4
Search vendor "Libpng" for product "Libpng" and version "1.6.4"
-
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.4
Search vendor "Libpng" for product "Libpng" and version "1.6.4"
beta
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.5
Search vendor "Libpng" for product "Libpng" and version "1.6.5"
-
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.6
Search vendor "Libpng" for product "Libpng" and version "1.6.6"
-
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.7
Search vendor "Libpng" for product "Libpng" and version "1.6.7"
-
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.7
Search vendor "Libpng" for product "Libpng" and version "1.6.7"
beta
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.8
Search vendor "Libpng" for product "Libpng" and version "1.6.8"
-
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.8
Search vendor "Libpng" for product "Libpng" and version "1.6.8"
beta
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.9
Search vendor "Libpng" for product "Libpng" and version "1.6.9"
-
Affected
Libpng
Search vendor "Libpng"
Libpng
Search vendor "Libpng" for product "Libpng"
1.6.9
Search vendor "Libpng" for product "Libpng" and version "1.6.9"
beta
Affected