CVE-2014-0333

medium
Published 2014-02-27 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.0

Description

The png_push_read_chunk function in pngpread.c in the progressive decoder in libpng 1.6.x through 1.6.9 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an IDAT chunk with a length of zero.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27
{Vendor advisory: cret@cert.org โ€” ftp://ftp.simplesystems.org/pub/png/src/libpng16/patch-libpng16-vu684412.diff}

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.6.10-1
debian debianbullseyefixed1.6.10-1
debian debianforkyfixed1.6.10-1
debian debiansidfixed1.6.10-1
debian debiantrixiefixed1.6.10-1

Application impact

VendorProductVersionsFixed
libpnglibpng1.6.0
libpnglibpng1.6.1
libpnglibpng1.6.2
libpnglibpng1.6.3
libpnglibpng1.6.4
libpnglibpng1.6.5
libpnglibpng1.6.6
libpnglibpng1.6.7
libpnglibpng1.6.8
libpnglibpng1.6.9

References

CWEs

CWE-189

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.