Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
Configuration 8 (hide)
|
Configuration 9 (hide)
|
Configuration 10 (hide)
|
History
21 Nov 2024, 02:38
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174435.html - | |
References | () http://sourceforge.net/p/libpng/bugs/244/ - | |
References | () http://sourceforge.net/p/libpng/code/ci/d9006f683c641793252d92254a75ae9b815b42ed/ - | |
References | () http://sourceforge.net/projects/libpng/files/libpng10/1.0.66/ - Patch | |
References | () http://sourceforge.net/projects/libpng/files/libpng12/1.2.56/ - Patch | |
References | () http://sourceforge.net/projects/libpng/files/libpng14/1.4.19/ - Patch | |
References | () http://sourceforge.net/projects/libpng/files/libpng15/1.5.26/ - Patch | |
References | () http://www.debian.org/security/2016/dsa-3443 - | |
References | () http://www.openwall.com/lists/oss-security/2015/12/10/6 - | |
References | () http://www.openwall.com/lists/oss-security/2015/12/10/7 - | |
References | () http://www.openwall.com/lists/oss-security/2015/12/11/1 - | |
References | () http://www.openwall.com/lists/oss-security/2015/12/11/2 - | |
References | () http://www.openwall.com/lists/oss-security/2015/12/17/10 - | |
References | () http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html - | |
References | () http://www.securityfocus.com/bid/80592 - | |
References | () https://access.redhat.com/errata/RHSA-2016:1430 - | |
References | () https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E - | |
References | () https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E - | |
References | () https://security.gentoo.org/glsa/201611-08 - |
07 Nov 2023, 02:28
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2016-04-14 14:59
Updated : 2024-11-21 02:38
NVD link : CVE-2015-8540
Mitre link : CVE-2015-8540
CVE.ORG link : CVE-2015-8540
JSON object : View
Products Affected
libpng
- libpng
redhat
- enterprise_linux_workstation_supplementary
- enterprise_linux_server_supplementary
- enterprise_linux_desktop_supplementary
- enterprise_linux_hpc_node
debian
- debian_linux
fedoraproject
- fedora
CWE
CWE-189
Numeric Errors