CVE-2015-8126

Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
libpnglibpng
𝑥
< 1.0.64
libpnglibpng
1.1.1 ≤
𝑥
< 1.2.54
libpnglibpng
1.3.0 ≤
𝑥
< 1.4.17
libpnglibpng
1.5.0 ≤
𝑥
< 1.5.24
libpnglibpng
1.6.0 ≤
𝑥
< 1.6.19
opensuseleap
42.1
opensuseopensuse
13.1
opensuseopensuse
13.2
debiandebian_linux
7.0
debiandebian_linux
8.0
debiandebian_linux
9.0
redhatsatellite
5.7
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_eus
6.7
redhatenterprise_linux_eus
7.2
redhatenterprise_linux_eus
7.3
redhatenterprise_linux_eus
7.4
redhatenterprise_linux_eus
7.5
redhatenterprise_linux_eus
7.6
redhatenterprise_linux_eus
7.7
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
7.2
redhatenterprise_linux_server_aus
7.3
redhatenterprise_linux_server_aus
7.4
redhatenterprise_linux_server_aus
7.6
redhatenterprise_linux_server_aus
7.7
redhatenterprise_linux_server_tus
7.2
redhatenterprise_linux_server_tus
7.3
redhatenterprise_linux_server_tus
7.6
redhatenterprise_linux_server_tus
7.7
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
redhatsatellite
5.6
oraclejdk
1.6.0
oraclejdk
1.7.0
oraclejdk
1.8.0
oraclejdk
1.8.0
oraclejre
1.6.0
oraclejre
1.7.0
oraclejre
1.8.0
oraclejre
1.8.0
oraclesolaris
11.3
applemac_os_x
𝑥
< 10.11.4
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
15.04
canonicalubuntu_linux
15.10
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
wily
not-affected
vivid
not-affected
trusty
dne
precise
not-affected
firefox
wily
not-affected
vivid
not-affected
trusty
dne
precise
not-affected
libpng
wily
Fixed 1.2.51-0ubuntu3.15.10.1
released
vivid
Fixed 1.2.51-0ubuntu3.15.04.1
released
trusty
Fixed 1.2.50-1ubuntu2.14.04.1
released
precise
Fixed 1.2.46-3ubuntu4.1
released
openjdk-6
wily
not-affected
vivid
not-affected
trusty
dne
precise
not-affected
openjdk-7
wily
not-affected
vivid
not-affected
trusty
dne
precise
not-affected
openjdk-8
wily
not-affected
vivid
not-affected
trusty
dne
precise
dne
thunderbird
wily
not-affected
vivid
not-affected
trusty
dne
precise
not-affected
References