CVE-2018-13785
In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.
- Affected products
- Alt Linux, Ibm Aix, Java Platform, Oracle Java Se, Red Hat, Suse, Ubuntu, Libpng
- Libpng
- = 1.6.34
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 4.5% (90th percentile)
- Weakness
- CWE-190, CWE-369
- NVD status
- Modified
- Published
- 2018-07-09
CVE-2018-13785 at NVD
No indexed exploits for CVE-2018-13785 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2018-13785 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.