search menu icon-carat-right cmu-wordmark

CERT Coordination Center

libpng denial-of-service vulnerability

Vulnerability Note VU#684412

Original Release Date: 2014-02-25 | Last Revised: 2014-02-25

Overview

libpng versions 1.6.0 through 1.6.9 contain a denial-of-service vulnerability.

Description

CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') - CVE-2014-0333

Glenn Randers Pehrson of the PNG Development Group reports:

The progressive decoder in libpng16 enters an infinite loop, thus hanging the application, when it encounters a zero-length IDAT chunk. Only libpng-1.6.0 and later are affected, and only applications using the progressive reader...The loop consumes CPU time but no memory or other resources.

Impact

Decoding a malformed .png file may cause the target application to become unresponsive.

Solution

Apply an Update
The PNG Development Group has released a patch to address this issue for libpng versions 1.6.0 through 1.6.9. The patch can be found at both simplesystems.org and the libpng Sourceforge project.

Vendor Information

684412
 

libpng Affected

Updated:  February 25, 2014

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.


CVSS Metrics

Group Score Vector
Base 4.3 AV:N/AC:M/Au:N/C:N/I:N/A:P
Temporal 3.6 E:F/RL:OF/RC:C
Environmental 3.6 CDP:N/TD:H/CR:ND/IR:ND/AR:ND

References

Acknowledgements

Thanks to Glenn Randers-Pehrson for reporting this vulnerability.

This document was written by Todd Lewellen.

Other Information

CVE IDs: CVE-2014-0333
Date Public: 2014-02-25
Date First Published: 2014-02-25
Date Last Updated: 2014-02-25 17:45 UTC
Document Revision: 5

Sponsored by CISA.