Описание
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | libpng | Will not fix | ||
| Red Hat Enterprise Linux 6 | libpng | Will not fix | ||
| Red Hat Enterprise Linux 7 | libpng | Will not fix | ||
| Red Hat Enterprise Linux 7 | libpng12 | Will not fix | ||
| Red Hat Enterprise Linux 8 | libpng | Not affected | ||
| Red Hat Enterprise Linux 8 | libpng12 | Will not fix | ||
| Red Hat Enterprise Linux 8 | libpng15 | Not affected | ||
| Red Hat Enterprise Linux 5 Supplementary | java-1.7.0-ibm | Fixed | RHSA-2016:0100 | 02.02.2016 |
| Red Hat Enterprise Linux 5 Supplementary | java-1.6.0-ibm | Fixed | RHSA-2016:0101 | 02.02.2016 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.7.1-ibm | Fixed | RHSA-2016:0099 | 02.02.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.6 High
CVSS3
5.4 Medium
CVSS2
Связанные уязвимости
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.
Integer underflow in the png_check_keyword function in pngwutil.c in l ...
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.
Уязвимость библиотеки libpng, позволяющая нарушителю повлиять на целостность, доступность и конфиденциальность информации
EPSS
7.6 High
CVSS3
5.4 Medium
CVSS2