CVE-2013-6954: Libpng

Medium severity, CVSS 6.5. EPSS: 4.7% chance of exploitation in the next 30 days.

The png_do_expand_palette function in libpng before 1.6.8 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via (1) a PLTE chunk of zero bytes or (2) a NULL palette, related to pngrtran.c and pngset.c.

Affected products

  • Libpng Libpng: up to and including 1.6.8; version 1.6.0 only; version 1.6.1 only; version 1.6.2 only; version 1.6.3 only; version 1.6.4 only; …

Published 2014-01-12. Last modified 2026-06-17.