CVE-2018-13785
published 2018-07-09CVE-2018-13785: In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
4.47%
90.4th percentile
In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libpng1.6 | < libpng1.6 1.6.34-2 (bookworm) | libpng1.6 1.6.34-2 (bookworm) |
| libpng | libpng | — | — |
| libpng | libpng | >= 0 < 1.2.50-1ubuntu2.14.04.3 | 1.2.50-1ubuntu2.14.04.3 |
| libpng | libpng | >= 0 < 1.2.54-1ubuntu1.1 | 1.2.54-1ubuntu1.1 |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fj59-ccrm-8h5w: In libpng 1
ghsa_unreviewed·2022-05-13
CVE-2018-13785 [MEDIUM] CWE-369 GHSA-fj59-ccrm-8h5w: In libpng 1
In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.
OSV
libpng, libpng1.6 vulnerabilities
osv·2018-07-11·CVSS 7.5
CVE-2016-10087 [HIGH] libpng, libpng1.6 vulnerabilities
libpng, libpng1.6 vulnerabilities
Patrick Keshishian discovered that libpng incorrectly handled certain PNG files.
An attacker could possibly use this to cause a denial of service. This issue
only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10087)
Thuan Pham discovered that libpng incorrectly handled certain PNG files.
An attacker could possibly use this to cause a denial of service.
This issue only affected Ubuntu 17.10 and Ubuntu 18.04 LTS.
(CVE-2018-13785)
OSV
CVE-2018-13785: In libpng 1
osv·2018-07-09·CVSS 6.5
CVE-2018-13785 [MEDIUM] CVE-2018-13785: In libpng 1
In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.
Ubuntu
libpng vulnerabilities
vendor_ubuntu·2018-07-11·CVSS 7.5
CVE-2016-10087 [HIGH] libpng vulnerabilities
Title: libpng vulnerabilities
Summary: Several security issues were fixed in libpng.
Patrick Keshishian discovered that libpng incorrectly handled certain PNG files.
An attacker could possibly use this to cause a denial of service. This issue
only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10087)
Thuan Pham discovered that libpng incorrectly handled certain PNG files.
An attacker could possibly use this to cause a denial of service.
This issue only affected Ubuntu 17.10 and Ubuntu 18.04 LTS.
(CVE-2018-13785)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service
vendor_redhat·2018-04-05·CVSS 6.5
CVE-2018-13785 [MEDIUM] CWE-190 libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service
libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service
In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.
Package: libpng (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-ibm (Red Hat Enterprise Linux 6) - Will not fix
Package: libpng (Red Hat Enterprise Linux 6) - Not affected
Package: libpng (Red Hat Enterprise Linux 7) - Not affected
Package: libpng12 (Red Hat Enterprise Linux 7) - Not affected
Package: libpng (Red Hat Enterprise Linux 8) - Not affected
Package: libpng12 (Red Hat Enterprise Linux 8) - Not affected
Pac
Debian
CVE-2018-13785: libpng1.6 - In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_lengt...
vendor_debian·2018·CVSS 6.5
CVE-2018-13785 [MEDIUM] CVE-2018-13785: libpng1.6 - In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_lengt...
In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.
Scope: local
bookworm: resolved (fixed in 1.6.34-2)
bullseye: resolved (fixed in 1.6.34-2)
forky: resolved (fixed in 1.6.34-2)
sid: resolved (fixed in 1.6.34-2)
trixie: resolved (fixed in 1.6.34-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-13785 libpng10: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [fedora-all]
bugzilla·2018-07-11·CVSS 6.5
CVE-2018-13785 [MEDIUM] CVE-2018-13785 libpng10: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [fedora-all]
CVE-2018-13785 libpng10: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog an
Bugzilla
CVE-2018-13785 mingw-libpng: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [epel-7]
bugzilla·2018-07-11·CVSS 6.5
CVE-2018-13785 [MEDIUM] CVE-2018-13785 mingw-libpng: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [epel-7]
CVE-2018-13785 mingw-libpng: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and th
Bugzilla
CVE-2018-13785 mingw-libpng: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [fedora-all]
bugzilla·2018-07-11·CVSS 6.5
CVE-2018-13785 [MEDIUM] CVE-2018-13785 mingw-libpng: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [fedora-all]
CVE-2018-13785 mingw-libpng: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelo
Bugzilla
CVE-2018-13785 libpng15: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [fedora-all]
bugzilla·2018-07-11·CVSS 6.5
CVE-2018-13785 [MEDIUM] CVE-2018-13785 libpng15: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [fedora-all]
CVE-2018-13785 libpng15: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog an
Bugzilla
CVE-2018-13785 libpng12: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [fedora-all]
bugzilla·2018-07-11·CVSS 6.5
CVE-2018-13785 [MEDIUM] CVE-2018-13785 libpng12: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [fedora-all]
CVE-2018-13785 libpng12: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog an
Bugzilla
CVE-2018-13785 libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service
bugzilla·2018-07-11·CVSS 6.5
CVE-2018-13785 [MEDIUM] CVE-2018-13785 libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service
CVE-2018-13785 libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service
libpng through version 1.6.34 is vulnerable to an integer overflow and resultant divide-by-zero in the pngrutil.c:png_check_chunk_length() function. An attacker could exploit this to cause a denial of service via crafted PNG file.
Upstream Bug:
https://sourceforge.net/p/libpng/bugs/278/
Upstream Patch:
https://github.com/glennrp/libpng/commit/8a05766cb74af05c04c53e6c9d60c13fc4d59bf2
Discussion:
Created libpng tracking bugs for this issue:
Affects: fedora-all [bug 1599944]
Created libpng10 tracking bugs for this issue:
Affects: epel-6 [bug 1599950]
Affects: fedora-all [bug 1599945]
Created libpng12 tracking bugs for this issue:
Affects: fed
Bugzilla
CVE-2018-13785 libpng10: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [epel-6]
bugzilla·2018-07-11·CVSS 6.5
CVE-2018-13785 [MEDIUM] CVE-2018-13785 libpng10: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [epel-6]
CVE-2018-13785 libpng10: libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fe
Bugzilla
CVE-2018-13785 libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [fedora-all]
bugzilla·2018-07-11·CVSS 6.5
CVE-2018-13785 [MEDIUM] CVE-2018-13785 libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [fedora-all]
CVE-2018-13785 libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedp
arXiv
Locus: Agentic Predicate Synthesis for Directed Fuzzing
arxiv_fulltext·2025-12-09
Locus: Agentic Predicate Synthesis for Directed Fuzzing
: Agentic Predicate Synthesis for Directed Fuzzing
Jie Zhu
University of Chicago
Chicago
USA
Chihao Shen
University of Maryland
College Park
USA
Ziyang Li
Johns Hopkins University
Baltimore
USA
Jiahao Yu
Northwestern University
Evanston
USA
Yizheng Chen
University of Maryland
College Park
USA
Kexin Pei
University of Chicago
Chicago
USA
Jie Zhu, Chihao Shen, Ziyang Li, Jiahao Yu, Yizheng Chen, Kexin Pei
## Abstract
Directed fuzzing aims to find program inputs that lead to specified target program states.
It has broad applications, such as debugging system crashes, confirming reported bugs, and generating exploits for potential vulnerabilities.
This task is inherently challenging because target states are often deeply nested in the program, while the search space manifested by
arXiv
Directed Greybox Fuzzing via Large Language Model
arxiv_fulltext·2025-05-06
Directed Greybox Fuzzing via Large Language Model
Directed Greybox Fuzzing via Large Language Model
Hanxiang Xu
Huazhong University of Science and Technology
China
[email protected]
Yanjie Zhao
Huazhong University of Science and Technology
China
[email protected]
Haoyu Wang
Huazhong University of Science and Technology
China
[email protected]
## Abstract
Directed greybox fuzzing (DGF) focuses on efficiently reaching specific program locations or triggering particular behaviors, making it essential for tasks like vulnerability detection and crash reproduction. However, existing methods often suffer from path explosion and randomness in input mutation, leading to inefficiencies in exploring and exploiting target paths. In this paper, we propose , an automatic framework that leverages the large language model (LLM) to add
arXiv
Magma: A Ground-Truth Fuzzing Benchmark
arxiv_fulltext·2020-10-23
Magma: A Ground-Truth Fuzzing Benchmark
: A Ground-Truth Fuzzing Benchmark
Ahmad Hazimeh
EPFLSwitzerland
[email protected]
Adrian Herrera
ANU & DSTAustralia
[email protected]
Mathias Payer
EPFLSwitzerland
[email protected]
## Abstract
High scalability and low running costs have made fuzz testing the de facto
standard for discovering software bugs. Fuzzing techniques are constantly being
improved in a race to build the ultimate bug-finding tool. However, while
fuzzing excels at finding bugs in the wild, evaluating and comparing fuzzer
performance is challenging due to the lack of metrics and benchmarks. For
example, crash count---perhaps the most commonly-used performance metric---is
inaccurate due to imperfections in deduplication techniques. Additionally, the
lack of a unified set of targets results in
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/105599http://www.securitytracker.com/id/1041889https://access.redhat.com/errata/RHSA-2018:3000https://access.redhat.com/errata/RHSA-2018:3001https://access.redhat.com/errata/RHSA-2018:3002https://access.redhat.com/errata/RHSA-2018:3003https://access.redhat.com/errata/RHSA-2018:3007https://access.redhat.com/errata/RHSA-2018:3008https://access.redhat.com/errata/RHSA-2018:3533https://access.redhat.com/errata/RHSA-2018:3534https://access.redhat.com/errata/RHSA-2018:3671https://access.redhat.com/errata/RHSA-2018:3672https://access.redhat.com/errata/RHSA-2018:3779https://access.redhat.com/errata/RHSA-2018:3852https://github.com/glennrp/libpng/commit/8a05766cb74af05c04c53e6c9d60c13fc4d59bf2https://security.gentoo.org/glsa/201908-10https://security.netapp.com/advisory/ntap-20181018-0001/https://sourceforge.net/p/libpng/bugs/278/https://usn.ubuntu.com/3712-1/http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/105599http://www.securitytracker.com/id/1041889https://access.redhat.com/errata/RHSA-2018:3000https://access.redhat.com/errata/RHSA-2018:3001https://access.redhat.com/errata/RHSA-2018:3002https://access.redhat.com/errata/RHSA-2018:3003https://access.redhat.com/errata/RHSA-2018:3007https://access.redhat.com/errata/RHSA-2018:3008https://access.redhat.com/errata/RHSA-2018:3533https://access.redhat.com/errata/RHSA-2018:3534https://access.redhat.com/errata/RHSA-2018:3671https://access.redhat.com/errata/RHSA-2018:3672https://access.redhat.com/errata/RHSA-2018:3779https://access.redhat.com/errata/RHSA-2018:3852https://github.com/glennrp/libpng/commit/8a05766cb74af05c04c53e6c9d60c13fc4d59bf2https://security.gentoo.org/glsa/201908-10https://security.netapp.com/advisory/ntap-20181018-0001/https://sourceforge.net/p/libpng/bugs/278/https://usn.ubuntu.com/3712-1/
2018-07-09
Published