libpng CVE-2019-6129 Denial of Service Vulnerability
BID:109212
Info
libpng CVE-2019-6129 Denial of Service Vulnerability
| Bugtraq ID: | 109212 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2019-6129 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2019 12:00AM |
| Updated: | Jan 11 2019 12:00AM |
| Credit: | Zerokeeper |
| Vulnerable: |
Oracle JRE(Windows Production Release) 12.0.1 Oracle JRE(Windows Production Release) 11.0.3 Oracle JRE(Windows Production Release) 1.8 Update 212 Oracle JRE(Windows Production Release) 1.7 Update 221 Oracle JRE(Solaris Production Release) 12.0.1 Oracle JRE(Solaris Production Release) 11.0.3 Oracle JRE(Solaris Production Release) 1.8 Update 212 Oracle JRE(Solaris Production Release) 1.7 Update 221 Oracle JRE(macOS Production Release) 12.0.1 Oracle JRE(macOS Production Release) 11.0.3 Oracle JRE(macOS Production Release) 1.8 Update 212 Oracle JRE(macOS Production Release) 1.7 Update 221 Oracle JRE(Linux Production Release) 12.0.1 Oracle JRE(Linux Production Release) 11.0.3 Oracle JRE(Linux Production Release) 1.8 Update 212 Oracle JRE(Linux Production Release) 1.7 Update 221 Oracle JDK(Windows Production Release) 12.0.1 Oracle JDK(Windows Production Release) 11.0.3 Oracle JDK(Windows Production Release) 1.8 Update 212 Oracle JDK(Windows Production Release) 1.7 Update 221 Oracle JDK(Solaris Production Release) 12.0.1 Oracle JDK(Solaris Production Release) 11.0.3 Oracle JDK(Solaris Production Release) 1.8 Update 212 Oracle JDK(Solaris Production Release) 1.7 Update 221 Oracle JDK(macOS Production Release) 12.0.1 Oracle JDK(macOS Production Release) 11.0.3 Oracle JDK(macOS Production Release) 1.8 Update 212 Oracle JDK(macOS Production Release) 1.7 Update 221 Oracle JDK(Linux Production Release) 12.0.1 Oracle JDK(Linux Production Release) 11.0.3 Oracle JDK(Linux Production Release) 1.8 Update 212 Oracle JDK(Linux Production Release) 1.7 Update 221 Oracle Java SE Embedded 8u211 libpng libpng 1.6.36 |
| Not Vulnerable: | |
Discussion
libpng CVE-2019-6129 Denial of Service Vulnerability
libpng is prone to a denial-of-service vulnerability.
An attacker may exploit this issue to crash the affected application, resulting in a denial-of-service condition.
libpng version 1.6.36 is vulnerable; other versions may also be affected.
libpng is prone to a denial-of-service vulnerability.
An attacker may exploit this issue to crash the affected application, resulting in a denial-of-service condition.
libpng version 1.6.36 is vulnerable; other versions may also be affected.
Exploit / POC
libpng CVE-2019-6129 Denial of Service Vulnerability
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
References
libpng CVE-2019-6129 Denial of Service Vulnerability
References:
References:
- Bug 1667127 (CVE-2019-6129) - CVE-2019-6129 libpng: memory leak of png_info stru (Red Hat)
- CVE-2019-6129 (Red Hat Bugzilla)
- memory leak in png_create_info_struct (libpng)
- Oracle Critical Patch Update Advisory - July 2019 (Oracle)