Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
Configuration 8 (hide)
|
Configuration 9 (hide)
|
Configuration 10 (hide)
|
History
21 Nov 2024, 02:38
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174435.html - | |
References | () http://sourceforge.net/p/libpng/bugs/244/ - | |
References | () http://sourceforge.net/p/libpng/code/ci/d9006f683c641793252d92254a75ae9b815b42ed/ - | |
References | () http://sourceforge.net/projects/libpng/files/libpng10/1.0.66/ - Patch | |
References | () http://sourceforge.net/projects/libpng/files/libpng12/1.2.56/ - Patch | |
References | () http://sourceforge.net/projects/libpng/files/libpng14/1.4.19/ - Patch | |
References | () http://sourceforge.net/projects/libpng/files/libpng15/1.5.26/ - Patch | |
References | () http://www.debian.org/security/2016/dsa-3443 - | |
References | () http://www.openwall.com/lists/oss-security/2015/12/10/6 - | |
References | () http://www.openwall.com/lists/oss-security/2015/12/10/7 - | |
References | () http://www.openwall.com/lists/oss-security/2015/12/11/1 - | |
References | () http://www.openwall.com/lists/oss-security/2015/12/11/2 - | |
References | () http://www.openwall.com/lists/oss-security/2015/12/17/10 - | |
References | () http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html - | |
References | () http://www.securityfocus.com/bid/80592 - | |
References | () https://access.redhat.com/errata/RHSA-2016:1430 - | |
References | () https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E - | |
References | () https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E - | |
References | () https://security.gentoo.org/glsa/201611-08 - |
Information
Published : 2016-04-14 14:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-8540
Mitre link : CVE-2015-8540
CVE.ORG link : CVE-2015-8540
JSON object : View
Products Affected
redhat
- enterprise_linux_hpc_node
- enterprise_linux_desktop_supplementary
- enterprise_linux_server_supplementary
- enterprise_linux_workstation_supplementary
debian
- debian_linux
libpng
- libpng
fedoraproject
- fedora
CWE
CWE-189
Numeric Errors