Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-0973

Опубликовано: 18 янв. 2015
Источник: debian
EPSS Низкий

Описание

Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libpngnot-affectedpackage
libpng1.6fixed1.6.16-1package
iceweaselnot-affectedpackage
icedovenot-affectedpackage
texlive-binfixed2014.20140926.35254-6package
texlive-binnot-affectedsqueezepackage
texlive-binnot-affectedwheezypackage

Примечания

  • http://tfpwn.com/files/libpng_heap_overflow_1.6.15.txt

  • http://mid.gmane.org/Pine.LNX.4.64.1501101510150.31425@beijing.mitre.org

EPSS

Процентиль: 83%
0.02006
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 11 лет назад

Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.

redhat
около 11 лет назад

Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.

CVSS3: 8.8
nvd
около 11 лет назад

Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.

CVSS3: 8.8
github
больше 3 лет назад

Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.

fstec
около 11 лет назад

Уязвимость библиотеки libpng, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 83%
0.02006
Низкий