CVE-2013-7353: Buffer Overflow
Published May 6, 2014
·Updated
Integer overflow in the pngsetunknownchunks function in libpng/pngset.c in libpng before 1.5.14beta08 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a crafted image, which triggers a heap-based buffer overflow.
Affected Software
24 affected components
libpng LIBPNG<=1.5.13
libpng LIBPNG=1.5.0-beta
libpng LIBPNG=1.5.1
libpng LIBPNG=1.5.1-beta
libpng LIBPNG=1.5.2
libpng LIBPNG=1.5.2-beta
libpng LIBPNG=1.5.3-beta
libpng LIBPNG=1.5.4
libpng LIBPNG=1.5.4-beta
libpng LIBPNG=1.5.5
libpng LIBPNG=1.5.5-beta
libpng LIBPNG=1.5.6
libpng LIBPNG=1.5.6-beta
libpng LIBPNG=1.5.7
libpng LIBPNG=1.5.7-beta
libpng LIBPNG=1.5.8
libpng LIBPNG=1.5.8-beta
libpng LIBPNG=1.5.9
libpng LIBPNG=1.5.9-beta
libpng LIBPNG=1.5.10-beta
libpng LIBPNG=1.5.11
libpng LIBPNG=1.5.11-beta
libpng LIBPNG=1.5.12
libpng LIBPNG=1.5.13-beta
Event History
May 6, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-7353?
CVE-2013-7353 has a severity rating that may lead to denial of service attacks due to a segmentation fault and crash.
2
How do I fix CVE-2013-7353?
To fix CVE-2013-7353, upgrade to libpng version 1.5.14beta08 or later.
3
What type of vulnerability is CVE-2013-7353?
CVE-2013-7353 is categorized as an integer overflow vulnerability causing a heap-based buffer overflow.
4
Which versions of libpng are impacted by CVE-2013-7353?
CVE-2013-7353 affects libpng versions up to and including 1.5.13 and certain beta versions.
5
What kind of attacks can CVE-2013-7353 facilitate?
CVE-2013-7353 can be exploited by attackers to create crafted images that lead to application crashes.