PT-2015-3270 · Png Development+6 · Libpng+6

Adam Mariš

·

Published

2015-12-05

·

Updated

2024-09-06

·

CVE-2015-8472

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libpng versions 1.0.0 through 1.0.64 libpng versions 1.1.x libpng versions 1.2.x through 1.2.54 libpng versions 1.3.x libpng versions 1.4.x through 1.4.17 libpng versions 1.5.x through 1.5.24 libpng versions 1.6.x through 1.6.19
Description The issue is caused by a buffer overflow in the png set PLTE function in libpng, allowing remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image. This vulnerability exists because of an incomplete fix for a previous issue.
Recommendations For libpng versions 1.0.0 through 1.0.64, update to version 1.0.65 or later. For libpng versions 1.1.x, update to version 1.2.55 or later. For libpng versions 1.2.x through 1.2.54, update to version 1.2.55 or later. For libpng versions 1.3.x, update to version 1.4.18 or later. For libpng versions 1.4.x through 1.4.17, update to version 1.4.18 or later. For libpng versions 1.5.x through 1.5.24, update to version 1.5.25 or later. For libpng versions 1.6.x through 1.6.19, update to version 1.6.20 or later. As a temporary workaround, consider disabling the png set PLTE function until a patch is available.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2068
ALT-PU-2019-1318
AZL-44394
BDU:2016-01664
CESA-2015_2594
CESA-2015_2595
CESA-2015_2596
CVE-2015-8472
DLA-375-1
DLA-410-1
DSA-3443-1
MGASA-2015-0473
OESA-2024-2091
OPENSUSE-SU-2016_0263-1
OPENSUSE-SU-2016_0268-1
OPENSUSE-SU-2016_0270-1
OPENSUSE-SU-2016_0272-1
OPENSUSE-SU-2016_0279-1
OPENSUSE-SU-2024:10534-1
RHSA-2015:2594
RHSA-2015:2595
RHSA-2015:2596
RHSA-2015_2594
RHSA-2015_2595
RHSA-2015_2596
RHSA-2016:0055
RHSA-2016:0056
RHSA-2016:0057
RHSA-2016:0098
RHSA-2016:0099
RHSA-2016:0100
RHSA-2016:0101
RHSA-2016:1430
RHSA-2016_0055
RHSA-2016_0056
RHSA-2016_0057
RHSA-2016_0098
RHSA-2016_0099
RHSA-2016_0101
SUSE-SU-2016:0265-1
SUSE-SU-2016:0269-1
SUSE-SU-2016:0390-1
SUSE-SU-2016:0399-1
SUSE-SU-2016:0401-1
SUSE-SU-2016:0428-1
SUSE-SU-2016:0431-1
SUSE-SU-2016:0433-1
SUSE-SU-2016:0636-1
SUSE-SU-2016:0770-1
USN-2861-1

Affected Products

Alt Linux
Centos
Ibm Aix
Red Hat
Suse
Ubuntu
Libpng