Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-2158

Опубликовано: 28 янв. 2015
Источник: redhat
CVSS2: 4.4

Описание

Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file.

Отчет

This issue did not affect the versions of pngcrush as shipped with Red Hat Enterprise Linux 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7pngcrushNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-193->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1198171pngcrush: pngcrush_measure_idat() off-by-one error

4.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 8 лет назад

Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file.

CVSS3: 7.8
nvd
около 8 лет назад

Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file.

CVSS3: 7.8
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 7.8
debian
около 8 лет назад

Off-by-one error in the pngcrush_measure_idat function in pngcrush.c i ...

CVSS3: 7.8
github
больше 3 лет назад

Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file.

4.4 Medium

CVSS2