[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-8126Date: (C)2015-12-15   (M)2024-03-22


Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1034142
BID-77568
APPLE-SA-2016-03-21-5
DSA-3399
DSA-3507
FEDORA-2015-13668fff74
FEDORA-2015-1d87313b7c
FEDORA-2015-233750b6ab
FEDORA-2015-4ad4998d00
FEDORA-2015-501493d853
FEDORA-2015-5e52306c9c
FEDORA-2015-8a1243db75
FEDORA-2015-97fc1797fa
FEDORA-2015-c80ec85542
FEDORA-2015-ec2ddd15d7
FEDORA-2016-43735c33a7
FEDORA-2016-9a1c707b10
GLSA-201603-09
GLSA-201611-08
RHSA-2015:2594
RHSA-2015:2595
RHSA-2015:2596
RHSA-2016:0055
RHSA-2016:0056
RHSA-2016:0057
RHSA-2016:1430
SUSE-SU-2016:0256
SUSE-SU-2016:0265
SUSE-SU-2016:0269
SUSE-SU-2016:0665
USN-2815-1
http://www.openwall.com/lists/oss-security/2015/11/12/2
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
https://code.google.com/p/chromium/issues/detail?id=560291
https://kc.mcafee.com/corporate/index?page=content&id=SB10148
https://support.apple.com/HT206167
openSUSE-SU-2015:2099
openSUSE-SU-2015:2100
openSUSE-SU-2015:2135
openSUSE-SU-2015:2136
openSUSE-SU-2015:2262
openSUSE-SU-2015:2263
openSUSE-SU-2016:0103
openSUSE-SU-2016:0104
openSUSE-SU-2016:0105
openSUSE-SU-2016:0263
openSUSE-SU-2016:0268
openSUSE-SU-2016:0270
openSUSE-SU-2016:0272
openSUSE-SU-2016:0279
openSUSE-SU-2016:0664
openSUSE-SU-2016:0684
openSUSE-SU-2016:0729

CPE    2
cpe:/a:libpng:libpng:1.6.18
cpe:/o:apple:mac_os_x:10.11.3
CWE    1
CWE-119
OVAL    53
oval:org.secpod.oval:def:110049
oval:org.secpod.oval:def:602338
oval:org.secpod.oval:def:109859
oval:org.secpod.oval:def:109817
...

© SecPod Technologies