The png_push_read_chunk function in pngpread.c in the progressive decoder in libpng 1.6.x through 1.6.9 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an IDAT chunk with a length of zero.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published: 2014-02-27T20:00:00

Updated: 2024-08-06T09:13:10.390Z

Reserved: 2013-12-05T00:00:00

Link: CVE-2014-0333

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2014-02-27T20:55:04.850

Modified: 2014-03-26T04:56:09.813

Link: CVE-2014-0333

cve-icon Redhat

Severity : Moderate

Publid Date: 2014-02-25T00:00:00Z

Links: CVE-2014-0333 - Bugzilla