Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-13785

Опубликовано: 05 апр. 2018
Источник: redhat
CVSS3: 6.5

Описание

In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libpngNot affected
Red Hat Enterprise Linux 6java-1.6.0-ibmWill not fix
Red Hat Enterprise Linux 6libpngNot affected
Red Hat Enterprise Linux 7libpngNot affected
Red Hat Enterprise Linux 7libpng12Not affected
Red Hat Enterprise Linux 8libpngNot affected
Red Hat Enterprise Linux 8libpng12Not affected
Red Hat Virtualization 4libpngNot affected
Oracle Java for Red Hat Enterprise Linux 6java-1.7.0-oracleFixedRHSA-2018:300024.10.2018
Oracle Java for Red Hat Enterprise Linux 6java-1.8.0-oracleFixedRHSA-2018:300324.10.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190->CWE-369
https://bugzilla.redhat.com/show_bug.cgi?id=1599943libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.

CVSS3: 6.5
nvd
больше 7 лет назад

In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.

CVSS3: 6.5
debian
больше 7 лет назад

In libpng 1.6.34, a wrong calculation of row_factor in the png_check_c ...

CVSS3: 6.5
github
больше 3 лет назад

In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.

suse-cvrf
больше 6 лет назад

Security update for libpng16

6.5 Medium

CVSS3