libpng: unhandled zero-length PLTE chunk or NULL palette
Published Jan 12, 2014
6.5
MEDIUMCVSS 3.1
EPSS 4.69%
Description
The png_do_expand_palette function in libpng before 1.6.8 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via (1) a PLTE chunk of zero bytes or (2) a NULL palette, related to pngrtran.c and pngset.c.
Affected products
No data.
- ≤ 1.6.8
- 1.6.0
- 1.6.0
- 1.6.1
- 1.6.1
- 1.6.2
- 1.6.2
- 1.6.3
- 1.6.3
- 1.6.4
- 1.6.4
- 1.6.5
- 1.6.6
- 1.6.7
- 1.6.7
No data.
Oracle Java for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.75-1jpp.3.el5_10
Fixed · RHSA-2014:0414
Oracle Java for Red Hat Enterprise Linux 5
java-1.7.0-oracle-1:1.7.0.55-1jpp.2.el5_10
Fixed · RHSA-2014:0413
Oracle Java for Red Hat Enterprise Linux 6
java-1.6.0-sun-1:1.6.0.75-1jpp.1.el6_5
Fixed · RHSA-2014:0414
Oracle Java for Red Hat Enterprise Linux 6
java-1.7.0-oracle-1:1.7.0.55-1jpp.1.el6_5
Fixed · RHSA-2014:0413
Red Hat Network Satellite Server v 5.4
java-1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el5
Fixed · RHSA-2014:0982
Red Hat Network Satellite Server v 5.5
java-1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el5
Fixed · RHSA-2014:0982
Red Hat Satellite 5.6
java-1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el5
Fixed · RHSA-2014:0982
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el5_10
Fixed · RHSA-2014:0508
Supplementary for Red Hat Enterprise Linux 5
java-1.7.0-ibm-1:1.7.0.7.0-1jpp.1.el5_10
Fixed · RHSA-2014:0486
Supplementary for Red Hat Enterprise Linux 5
java-1.7.0-oracle-1:1.7.0.55-1jpp.2.el5_10
Fixed · RHSA-2014:0412
Supplementary for Red Hat Enterprise Linux 6
java-1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el6_5
Fixed · RHSA-2014:0508
Supplementary for Red Hat Enterprise Linux 6
java-1.7.0-ibm-1:1.7.0.7.0-1jpp.1.el6_5
Fixed · RHSA-2014:0486
Supplementary for Red Hat Enterprise Linux 6
java-1.7.0-oracle-1:1.7.0.55-1jpp.1.el6_5
Fixed · RHSA-2014:0412
Supplementary for Red Hat Enterprise Linux 7
java-1.7.1-ibm-1:1.7.1.1.0-1jpp.2.el7_0
Fixed · RHSA-2014:0705
Red Hat Enterprise Linux 5
java-1.5.0-ibm
Not affected
Red Hat Enterprise Linux 5
libpng
Not affected
Red Hat Enterprise Linux 6
java-1.5.0-ibm
Not affected
Red Hat Enterprise Linux 6
libpng
Not affected
Red Hat Enterprise Linux 7
libpng
Not affected
Red Hat Enterprise Linux 7
libpng12
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Oracle Java for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.75-1jpp.3.el5_10 | Fixed | RHSA-2014:0414 |
| Oracle Java for Red Hat Enterprise Linux 5 | java-1.7.0-oracle-1:1.7.0.55-1jpp.2.el5_10 | Fixed | RHSA-2014:0413 |
| Oracle Java for Red Hat Enterprise Linux 6 | java-1.6.0-sun-1:1.6.0.75-1jpp.1.el6_5 | Fixed | RHSA-2014:0414 |
| Oracle Java for Red Hat Enterprise Linux 6 | java-1.7.0-oracle-1:1.7.0.55-1jpp.1.el6_5 | Fixed | RHSA-2014:0413 |
| Red Hat Network Satellite Server v 5.4 | java-1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el5 | Fixed | RHSA-2014:0982 |
| Red Hat Network Satellite Server v 5.5 | java-1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el5 | Fixed | RHSA-2014:0982 |
| Red Hat Satellite 5.6 | java-1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el5 | Fixed | RHSA-2014:0982 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el5_10 | Fixed | RHSA-2014:0508 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.7.0-ibm-1:1.7.0.7.0-1jpp.1.el5_10 | Fixed | RHSA-2014:0486 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.7.0-oracle-1:1.7.0.55-1jpp.2.el5_10 | Fixed | RHSA-2014:0412 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el6_5 | Fixed | RHSA-2014:0508 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.7.0-ibm-1:1.7.0.7.0-1jpp.1.el6_5 | Fixed | RHSA-2014:0486 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.7.0-oracle-1:1.7.0.55-1jpp.1.el6_5 | Fixed | RHSA-2014:0412 |
| Supplementary for Red Hat Enterprise Linux 7 | java-1.7.1-ibm-1:1.7.1.1.0-1jpp.2.el7_0 | Fixed | RHSA-2014:0705 |
| Red Hat Enterprise Linux 5 | java-1.5.0-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 5 | libpng | Not affected | n/a |
| Red Hat Enterprise Linux 6 | java-1.5.0-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 6 | libpng | Not affected | n/a |
| Red Hat Enterprise Linux 7 | libpng | Not affected | n/a |
| Red Hat Enterprise Linux 7 | libpng12 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not Vulnerable. This issue does not affect the version of libpng as shipped with Red Hat Enterprise Linux 5 and 6.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jun 9, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.69% (0.04692) | 91.51th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.89% (0.04894) | 90.93th | v5 (v2026.06.15) |
| Jun 11, 2025 | 3.55% (0.03546) | 87.14th | v4 (v2025.03.14) |
| Mar 30, 2025 | 7.09% (0.07090) | 90.65th | v4 (v2025.03.14) |
| Mar 29, 2025 | 11.19% (0.11187) | 89.13th | v4 (v2025.03.14) |
| Mar 17, 2025 | 7.09% (0.07090) | 90.86th | v4 (v2025.03.14) |
| Dec 17, 2024 | 14.58% (0.14580) | 95.74th | v3 (v2023.03.01) |
| Jan 11, 2024 | 13.29% (0.13292) | 95.05th | v3 (v2023.03.01) |
| Aug 25, 2023 | 10.43% (0.10427) | 94.25th | v3 (v2023.03.01) |
| Mar 7, 2023 | 12.02% (0.12022) | 94.41th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
References (28)
- http://advisories.mageia.org/MGASA-2014-0075.html x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127947.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127952.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128098.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128099.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128114.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00071.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=140852886808946&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=140852974709252&w=2 vendor-advisoryx_refsource_HP
- http://secunia.com/advisories/58974 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59058 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201406-32.xml vendor-advisoryx_refsource_GENTOO
- http://sourceforge.net/p/libpng/code/ci/1faa6ff32c648acfe3cf30a58d31d7aebc24968c x_refsource_CONFIRMExploitPatch
- http://sourceforge.net/projects/libpng/files/libpng16/1.6.8/ x_refsource_CONFIRMPatch
- http://www-01.ibm.com/support/docview.wss?uid=swg21672080 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676746 x_refsource_CONFIRM
- http://www.kb.cert.org/vuls/id/650142 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.libpng.org/pub/png/libpng.html x_refsource_MISC
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:035 vendor-advisoryx_refsource_MANDRIVA
- http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/64493 vdb-entryx_refsource_BID
- https://access.redhat.com/errata/RHSA-2014:0413 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2014:0414 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2013-6954 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1045561 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-6954
- https://www.cve.org/CVERecord?id=CVE-2013-6954
- https://www.ibm.com/support/docview.wss?uid=swg21675973 x_refsource_CONFIRM
Change history (0)
No recorded changes yet.