PT-2015-3270 · Png Development+6 · Libpng+6

Adam Mariš

·

Publicado

2015-12-05

·

Atualizado

2024-09-06

·

CVE-2015-8472

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libpng versions 1.0.0 through 1.0.64 libpng versions 1.1.x libpng versions 1.2.x through 1.2.54 libpng versions 1.3.x libpng versions 1.4.x through 1.4.17 libpng versions 1.5.x through 1.5.24 libpng versions 1.6.x through 1.6.19
Description The issue is caused by a buffer overflow in the png set PLTE function in libpng, allowing remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image. This vulnerability exists because of an incomplete fix for a previous issue.
Recommendations For libpng versions 1.0.0 through 1.0.64, update to version 1.0.65 or later. For libpng versions 1.1.x, update to version 1.2.55 or later. For libpng versions 1.2.x through 1.2.54, update to version 1.2.55 or later. For libpng versions 1.3.x, update to version 1.4.18 or later. For libpng versions 1.4.x through 1.4.17, update to version 1.4.18 or later. For libpng versions 1.5.x through 1.5.24, update to version 1.5.25 or later. For libpng versions 1.6.x through 1.6.19, update to version 1.6.20 or later. As a temporary workaround, consider disabling the png set PLTE function until a patch is available.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-2068
ALT-PU-2019-1318
AZL-44394
BDU:2016-01664
CESA-2015_2594
CESA-2015_2595
CESA-2015_2596
CVE-2015-8472
DLA-375-1
DLA-410-1
DSA-3443-1
MGASA-2015-0473
OESA-2024-2091
OPENSUSE-SU-2016_0263-1
OPENSUSE-SU-2016_0268-1
OPENSUSE-SU-2016_0270-1
OPENSUSE-SU-2016_0272-1
OPENSUSE-SU-2016_0279-1
OPENSUSE-SU-2024:10534-1
RHSA-2015:2594
RHSA-2015:2595
RHSA-2015:2596
RHSA-2015_2594
RHSA-2015_2595
RHSA-2015_2596
RHSA-2016:0055
RHSA-2016:0056
RHSA-2016:0057
RHSA-2016:0098
RHSA-2016:0099
RHSA-2016:0100
RHSA-2016:0101
RHSA-2016:1430
RHSA-2016_0055
RHSA-2016_0056
RHSA-2016_0057
RHSA-2016_0098
RHSA-2016_0099
RHSA-2016_0101
SUSE-SU-2016:0265-1
SUSE-SU-2016:0269-1
SUSE-SU-2016:0390-1
SUSE-SU-2016:0399-1
SUSE-SU-2016:0401-1
SUSE-SU-2016:0428-1
SUSE-SU-2016:0431-1
SUSE-SU-2016:0433-1
SUSE-SU-2016:0636-1
SUSE-SU-2016:0770-1
USN-2861-1

Produtos afetados

Alt Linux
Centos
Ibm Aix
Red Hat
Suse
Ubuntu
Libpng