SB2014022502 - Input validation error in libpng (Alpine package)
Published: February 25, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2013-6954)
The vulnerability allows remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (NULL pointer dereference and application crash) via (1) a PLTE chunk of zero bytes or (2) a NULL palette, related to pngrtran.c and pngset.c.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=4caf03d1ac6af8d42281f2154cce32d83ca8a2d2
- https://git.alpinelinux.org/aports/commit/?id=7f7d47bce8ceac1f164300401f93e3b4befe3dd7
- https://git.alpinelinux.org/aports/commit/?id=ea0840f0c9ffe19d99977e57efc43f51297b47e1
- https://git.alpinelinux.org/aports/commit/?id=93a749c100d8fc7a2967cfa7474f577df890a53d