[v2.5] libpng: remote DoS (CVE-2013-6954)
The png_do_expand_palette function in libpng before 1.6.8 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via (1) a PLTE chunk of zero bytes or (2) a NULL palette, related to pngrtran.c and pngset.c.
•MISC: http://www.libpng.org/pub/png/libpng.html
•CONFIRM:
http://sourceforge.net/p/libpng/code/ci/1faa6ff32c648acfe3cf30a58d31d7aebc24968c
•CONFIRM: http://sourceforge.net/projects/libpng/files/libpng16/1.6.8/
•CONFIRM: https://bugzilla.redhat.com/show\_bug.cgi?id=1045561
•CONFIRM: http://advisories.mageia.org/MGASA-2014-0075.html
•FEDORA:FEDORA-2014-1754
•URL:
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127947.html
•FEDORA:FEDORA-2014-1766
•URL:
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128114.html
•FEDORA:FEDORA-2014-1770
•URL:
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128099.html
•FEDORA:FEDORA-2014-1778
•URL:
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127952.html
•FEDORA:FEDORA-2014-1803
•URL:
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128098.html
•MANDRIVA:MDVSA-2014:035
•URL: http://www.mandriva.com/security/advisories?name=MDVSA-2014:035
•CERT-VN:VU#650142
•URL: http://www.kb.cert.org/vuls/id/650142
•BID:64493
•URL: http://www.securityfocus.com/bid/64493
(from redmine: issue id 2698, created on 2014-02-21, closed on 2014-03-03)
- Relations:
- parent #2696 (closed)
- Changesets:
- Revision ea0840f0 by Natanael Copa on 2014-02-25T16:56:34Z:
main/libpng: security fix for CVE-2013-6954
fixes #2698