[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-8472Date: (C)2016-02-11   (M)2024-02-01


Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8126.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.3CVSS Score : 7.5
Exploit Score: 3.9Exploit Score: 10.0
Impact Score: 3.4Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: LOWAvailability: PARTIAL
Integrity: LOW 
Availability: LOW 
  
Reference:
BID-78624
APPLE-SA-2016-03-21-5
DSA-3443
FEDORA-2015-233750b6ab
FEDORA-2015-4ad4998d00
FEDORA-2015-c80ec85542
RHSA-2015:2594
RHSA-2015:2595
RHSA-2015:2596
RHSA-2016:0055
RHSA-2016:0056
RHSA-2016:0057
RHSA-2016:1430
SUSE-SU-2016:0256
SUSE-SU-2016:0265
SUSE-SU-2016:0269
http://www.openwall.com/lists/oss-security/2015/12/03/6
http://sourceforge.net/projects/libpng/files/libpng10/1.0.65/
http://sourceforge.net/projects/libpng/files/libpng12/1.2.55/
http://sourceforge.net/projects/libpng/files/libpng14/1.4.18/
http://sourceforge.net/projects/libpng/files/libpng15/1.5.25/
http://sourceforge.net/projects/libpng/files/libpng16/1.6.20/
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
https://kc.mcafee.com/corporate/index?page=content&id=SB10148
https://support.apple.com/HT206167
openSUSE-SU-2016:0263
openSUSE-SU-2016:0268
openSUSE-SU-2016:0270
openSUSE-SU-2016:0272
openSUSE-SU-2016:0279

CPE    110
cpe:/a:libpng:libpng:1.2.38
cpe:/a:libpng:libpng:1.2.39
cpe:/a:libpng:libpng:1.2.34
cpe:/a:libpng:libpng:1.2.35
...
CWE    1
CWE-119
OVAL    32
oval:org.secpod.oval:def:110049
oval:org.secpod.oval:def:602338
oval:org.secpod.oval:def:109859
oval:org.secpod.oval:def:702907
...

© SecPod Technologies