Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8540

Опубликовано: 10 дек. 2015
Источник: redhat
CVSS3: 7.6
CVSS2: 5.4
EPSS Средний

Описание

Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libpngWill not fix
Red Hat Enterprise Linux 6libpngWill not fix
Red Hat Enterprise Linux 7libpngWill not fix
Red Hat Enterprise Linux 7libpng12Will not fix
Red Hat Enterprise Linux 8libpngNot affected
Red Hat Enterprise Linux 8libpng12Will not fix
Red Hat Enterprise Linux 8libpng15Not affected
Red Hat Enterprise Linux 5 Supplementaryjava-1.7.0-ibmFixedRHSA-2016:010002.02.2016
Red Hat Enterprise Linux 5 Supplementaryjava-1.6.0-ibmFixedRHSA-2016:010102.02.2016
Red Hat Enterprise Linux 6 Supplementaryjava-1.7.1-ibmFixedRHSA-2016:009902.02.2016

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1291312libpng: underflow read in png_check_keyword()

EPSS

Процентиль: 94%
0.14316
Средний

7.6 High

CVSS3

5.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 10 лет назад

Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.

CVSS3: 8.8
nvd
почти 10 лет назад

Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.

CVSS3: 8.8
debian
почти 10 лет назад

Integer underflow in the png_check_keyword function in pngwutil.c in l ...

CVSS3: 8.8
github
больше 3 лет назад

Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.

fstec
почти 10 лет назад

Уязвимость библиотеки libpng, позволяющая нарушителю повлиять на целостность, доступность и конфиденциальность информации

EPSS

Процентиль: 94%
0.14316
Средний

7.6 High

CVSS3

5.4 Medium

CVSS2