Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-8126

Опубликовано: 13 нояб. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.

РелизСтатусПримечание
devel

not-affected

uses system libpng
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [uses system libpng]]
precise

not-affected

uses system libpng
trusty

not-affected

uses system libpng
trusty/esm

DNE

trusty was not-affected [uses system libpng]
upstream

needs-triage

vivid

not-affected

uses system libpng
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

not-affected

uses system libpng

Показывать по

РелизСтатусПримечание
devel

not-affected

see note
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [see note]]
precise

not-affected

see note
trusty

not-affected

see note
trusty/esm

DNE

trusty was not-affected [see note]
upstream

not-affected

see note
vivid

not-affected

see note
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

not-affected

see note

Показывать по

РелизСтатусПримечание
devel

not-affected

1.2.54-1
esm-infra-legacy/trusty

not-affected

1.2.50-1ubuntu2.14.04.1
precise

released

1.2.46-3ubuntu4.1
trusty

released

1.2.50-1ubuntu2.14.04.1
trusty/esm

not-affected

1.2.50-1ubuntu2.14.04.1
upstream

released

1.6.19, 1.5.24, 1.4.17, 1.2.54, 1.0.64
vivid

released

1.2.51-0ubuntu3.15.04.1
vivid/stable-phone-overlay

released

1.2.51-0ubuntu3.15.04.2
vivid/ubuntu-core

released

1.2.51-0ubuntu3.15.04.1
wily

released

1.2.51-0ubuntu3.15.10.1

Показывать по

РелизСтатусПримечание
devel

not-affected

uses system libpng
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [uses system libpng]]
precise

not-affected

uses system libpng
trusty

not-affected

uses system libpng
trusty/esm

DNE

trusty was not-affected [uses system libpng]
upstream

needs-triage

vivid

not-affected

uses system libpng
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

not-affected

uses system libpng

Показывать по

РелизСтатусПримечание
devel

not-affected

uses system libpng
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [uses system libpng]]
precise

not-affected

uses system libpng
trusty

not-affected

uses system libpng
trusty/esm

DNE

trusty was not-affected [uses system libpng]
upstream

needs-triage

vivid

not-affected

uses system libpng
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

not-affected

uses system libpng

Показывать по

РелизСтатусПримечание
devel

not-affected

uses system libpng
esm-infra-legacy/trusty

DNE

precise

DNE

trusty

DNE

trusty/esm

DNE

upstream

needs-triage

vivid

not-affected

uses system libpng
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

not-affected

uses system libpng

Показывать по

РелизСтатусПримечание
devel

not-affected

see note
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [see note]]
precise

not-affected

see note
trusty

not-affected

see note
trusty/esm

DNE

trusty was not-affected [see note]
upstream

not-affected

see note
vivid

not-affected

see note
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

not-affected

see note

Показывать по

EPSS

Процентиль: 90%
0.05569
Низкий

7.5 High

CVSS2

Связанные уязвимости

redhat
больше 9 лет назад

Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.

nvd
больше 9 лет назад

Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.

msrc
3 месяца назад

Описание отсутствует

debian
больше 9 лет назад

Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE ...

suse-cvrf
больше 9 лет назад

Security update for libpng16

EPSS

Процентиль: 90%
0.05569
Низкий

7.5 High

CVSS2

Уязвимость CVE-2015-8126