Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2013-6954

The png_do_expand_palette function in libpng before 1.6.8 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via (1) a PLTE chunk of zero bytes or (2) a NULL palette, related to pngrtran.c and pngset.c.

  • Published: Jan 12, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2013-6954
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:N/A:P

No CWE or OWASP classifications available.

Software From Fixed in
libpng / libpng 1.6.0 1.6.0.x
libpng / libpng 1.6.1 1.6.1.x
libpng / libpng 1.6.3 1.6.3.x
libpng / libpng 1.6.0-beta 1.6.0-beta.x
libpng / libpng 1.6.4-beta 1.6.4-beta.x
libpng / libpng 1.6.7-beta 1.6.7-beta.x
libpng / libpng 1.6.1-beta 1.6.1-beta.x
libpng / libpng 1.6.6 1.6.6.x
libpng / libpng 1.6.7 1.6.7.x
libpng / libpng - 1.6.8.x
libpng / libpng 1.6.4 1.6.4.x
libpng / libpng 1.6.3-beta 1.6.3-beta.x
libpng / libpng 1.6.2-beta 1.6.2-beta.x
libpng / libpng 1.6.2 1.6.2.x
libpng / libpng 1.6.5 1.6.5.x