CVE-2015-8126
13.11.2015, 03:59
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.
Vendor | Product | Version |
---|---|---|
libpng | libpng | 𝑥 < 1.0.64 |
libpng | libpng | 1.1.1 ≤ 𝑥 < 1.2.54 |
libpng | libpng | 1.3.0 ≤ 𝑥 < 1.4.17 |
libpng | libpng | 1.5.0 ≤ 𝑥 < 1.5.24 |
libpng | libpng | 1.6.0 ≤ 𝑥 < 1.6.19 |
opensuse | leap | 42.1 |
opensuse | opensuse | 13.1 |
opensuse | opensuse | 13.2 |
debian | debian_linux | 7.0 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
redhat | satellite | 5.7 |
redhat | enterprise_linux_desktop | 6.0 |
redhat | enterprise_linux_desktop | 7.0 |
redhat | enterprise_linux_eus | 6.7 |
redhat | enterprise_linux_eus | 7.2 |
redhat | enterprise_linux_eus | 7.3 |
redhat | enterprise_linux_eus | 7.4 |
redhat | enterprise_linux_eus | 7.5 |
redhat | enterprise_linux_eus | 7.6 |
redhat | enterprise_linux_eus | 7.7 |
redhat | enterprise_linux_server | 6.0 |
redhat | enterprise_linux_server | 7.0 |
redhat | enterprise_linux_server_aus | 7.2 |
redhat | enterprise_linux_server_aus | 7.3 |
redhat | enterprise_linux_server_aus | 7.4 |
redhat | enterprise_linux_server_aus | 7.6 |
redhat | enterprise_linux_server_aus | 7.7 |
redhat | enterprise_linux_server_tus | 7.2 |
redhat | enterprise_linux_server_tus | 7.3 |
redhat | enterprise_linux_server_tus | 7.6 |
redhat | enterprise_linux_server_tus | 7.7 |
redhat | enterprise_linux_workstation | 6.0 |
redhat | enterprise_linux_workstation | 7.0 |
redhat | satellite | 5.6 |
oracle | jdk | 1.6.0 |
oracle | jdk | 1.7.0 |
oracle | jdk | 1.8.0 |
oracle | jdk | 1.8.0 |
oracle | jre | 1.6.0 |
oracle | jre | 1.7.0 |
oracle | jre | 1.8.0 |
oracle | jre | 1.8.0 |
oracle | solaris | 11.3 |
apple | mac_os_x | 𝑥 < 10.11.4 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 15.04 |
canonical | ubuntu_linux | 15.10 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||
---|---|---|---|---|---|---|---|---|---|
chromium-browser |
| ||||||||
firefox |
| ||||||||
libpng |
| ||||||||
openjdk-6 |
| ||||||||
openjdk-7 |
| ||||||||
openjdk-8 |
| ||||||||
thunderbird |
|
References