Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-13785

Опубликовано: 05 апр. 2018
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libpngNot affected
Red Hat Enterprise Linux 6java-1.6.0-ibmWill not fix
Red Hat Enterprise Linux 6libpngNot affected
Red Hat Enterprise Linux 7libpngNot affected
Red Hat Enterprise Linux 7libpng12Not affected
Red Hat Enterprise Linux 8libpngNot affected
Red Hat Enterprise Linux 8libpng12Not affected
Red Hat Virtualization 4libpngNot affected
Oracle Java for Red Hat Enterprise Linux 6java-1.7.0-oracleFixedRHSA-2018:300024.10.2018
Oracle Java for Red Hat Enterprise Linux 6java-1.8.0-oracleFixedRHSA-2018:300324.10.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-369
https://bugzilla.redhat.com/show_bug.cgi?id=1599943libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service

EPSS

Процентиль: 91%
0.0447
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 8 лет назад

In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.

CVSS3: 6.5
nvd
около 8 лет назад

In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.

CVSS3: 6.5
debian
около 8 лет назад

In libpng 1.6.34, a wrong calculation of row_factor in the png_check_c ...

CVSS3: 6.5
github
больше 4 лет назад

In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.

suse-cvrf
около 7 лет назад

Security update for libpng16

EPSS

Процентиль: 91%
0.0447
Низкий

6.5 Medium

CVSS3