HIGH · 7.5

CVE-2015-8126

Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x b...

Vulnerability Description

Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
LibpngLibpng< 1.0.64
FedoraprojectFedora21
OpensuseLeap42.1
OpensuseOpensuse13.1
SuseLinux Enterprise Desktop11
SuseLinux Enterprise Server12
DebianDebian Linux7.0
RedhatSatellite5.7
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Eus6.7
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server Aus7.2
RedhatEnterprise Linux Server Tus7.2
RedhatEnterprise Linux Workstation6.0
RedhatEnterprise Linux5.0
OracleJdk1.6.0
OracleJre1.6.0
OracleLinux6
OracleSolaris11.3
AppleMac Os X< 10.11.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-8126?

CVE-2015-8126 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x b...

How severe is CVE-2015-8126?

CVE-2015-8126 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-8126?

Check the references section above for vendor advisories and patch information. Affected products include: Libpng Libpng, Fedoraproject Fedora, Opensuse Leap, Opensuse Opensuse, Suse Linux Enterprise Desktop.