CVE-2014-0333: Medium severity libpng LIBPNG vulnerability
Published Feb 27, 2014
·Updated
The pngpushreadchunk function in pngpread.c in the progressive decoder in libpng 1.6.x through 1.6.9 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an IDAT chunk with a length of zero.
Affected Software
18 affected components
libpng LIBPNG=1.6.0
libpng LIBPNG=1.6.0-beta
libpng LIBPNG=1.6.1
libpng LIBPNG=1.6.1-beta
libpng LIBPNG=1.6.2
libpng LIBPNG=1.6.2-beta
libpng LIBPNG=1.6.3
libpng LIBPNG=1.6.3-beta
libpng LIBPNG=1.6.4
libpng LIBPNG=1.6.4-beta
libpng LIBPNG=1.6.5
libpng LIBPNG=1.6.6
libpng LIBPNG=1.6.7
libpng LIBPNG=1.6.7-beta
libpng LIBPNG=1.6.8
libpng LIBPNG=1.6.8-beta
libpng LIBPNG=1.6.9
libpng LIBPNG=1.6.9-beta
Remediation
Patch Available
Event History
Feb 27, 2014
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-0333?
CVE-2014-0333 has a medium severity rating due to the potential for denial of service through resource exhaustion.
2
How do I fix CVE-2014-0333?
To fix CVE-2014-0333, upgrade libpng to version 1.6.10 or later.
3
What software versions are affected by CVE-2014-0333?
CVE-2014-0333 affects libpng versions from 1.6.0 to 1.6.9 inclusive.
4
Is CVE-2014-0333 exploitable remotely?
Yes, CVE-2014-0333 can be exploited remotely through crafted PNG files containing an IDAT chunk with a length of zero.
5
What impact does CVE-2014-0333 have on systems?
CVE-2014-0333 can cause an infinite loop leading to high CPU consumption and potential denial of service on affected systems.