PT-2015-3261 · Libpng+5 · Libpng+5

Padma81

·

Publicado

2015-12-11

·

Atualizado

2024-09-06

·

CVE-2015-8540

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libpng versions 0.90 through 0.99 libpng versions 1.0.x before 1.0.66 libpng versions 1.1.x and 1.2.x before 1.2.56 libpng versions 1.3.x and 1.4.x before 1.4.19 libpng versions 1.5.x before 1.5.26
Description The issue is caused by an integer underflow in the png check keyword function in pngwutil.c, which allows remote attackers to have an unspecified impact via a space character as a keyword in a PNG image, triggering an out-of-bounds read. This could potentially affect the integrity, availability, and confidentiality of information. The vulnerability may be exploited by sending a specially crafted PNG image with a space character in the keyword.
Recommendations For libpng versions 0.90 through 0.99, update to a version outside of this range to mitigate the issue. For libpng versions 1.0.x before 1.0.66, update to version 1.0.66 or later. For libpng versions 1.1.x and 1.2.x before 1.2.56, update to version 1.2.56 or later. For libpng versions 1.3.x and 1.4.x before 1.4.19, update to version 1.4.19 or later. For libpng versions 1.5.x before 1.5.26, update to version 1.5.26 or later. As a temporary workaround, consider restricting the use of PNG images with space characters in keywords until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-2157
ALT-PU-2019-1318
BDU:2016-01652
CVE-2015-8540
DLA-375-1
DSA-3443-1
MGASA-2015-0489
OESA-2024-2091
RHSA-2016:0099
RHSA-2016:0100
RHSA-2016:0101
RHSA-2016:1430
RHSA-2016_0099
RHSA-2016_0101
SUSE-SU-2016:0399-1
SUSE-SU-2016:0401-1
SUSE-SU-2016:0428-1
SUSE-SU-2016:0431-1
SUSE-SU-2016:0433-1
SUSE-SU-2016:0636-1
SUSE-SU-2016:0770-1
SUSE-SU-2017:0860-1
SUSE-SU-2017:0901-1
SUSE-SU-2017:0950-1
SUSE-SU-2017_0860-1
SUSE-SU-2017_0901-1
SUSE-SU-2017_0950-1
USN-2861-1

Produtos afetados

Alt Linux
Ibm Aix
Red Hat
Suse
Ubuntu
Libpng