Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-2158

Опубликовано: 28 янв. 2015
Источник: redhat
CVSS2: 4.4
EPSS Низкий

Описание

Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file.

Отчет

This issue did not affect the versions of pngcrush as shipped with Red Hat Enterprise Linux 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7pngcrushNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-193->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1198171pngcrush: pngcrush_measure_idat() off-by-one error

EPSS

Процентиль: 67%
0.00551
Низкий

4.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file.

CVSS3: 7.8
nvd
больше 7 лет назад

Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file.

CVSS3: 7.8
msrc
3 месяца назад

Описание отсутствует

CVSS3: 7.8
debian
больше 7 лет назад

Off-by-one error in the pngcrush_measure_idat function in pngcrush.c i ...

CVSS3: 7.8
github
около 3 лет назад

Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file.

EPSS

Процентиль: 67%
0.00551
Низкий

4.4 Medium

CVSS2