{"id":"MGASA-2014-0131","summary":"Updated libpng package fixes security vulnerability","details":"The png_push_read_chunk function in pngpread.c in the progressive decoder\nin libpng 1.6.x through 1.6.9 allows remote attackers to cause a denial of\nservice (infinite loop and CPU consumption) via an IDAT chunk with a\nlength of zero (CVE-2014-0333).\n","modified":"2026-04-16T06:23:07.027101232Z","published":"2014-03-15T16:29:56Z","upstream":["CVE-2014-0333"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0131.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=13001"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2014-03/msg00029.html"}],"affected":[{"package":{"name":"libpng","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/libpng?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.8-1.1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0131.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}