CVE-2015-0973

HIGH

Oracle Solaris < 1.5.20 - Memory Corruption

Title source: rule
STIX 2.1

Description

Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.

Scores

CVSS v3 8.8
EPSS 0.0201
EPSS Percentile 83.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-119 CWE-120
Status published
Products (19)
apple/mac_os_x < 10.11.3
libpng/libpng 1.6.0 (2 CPE variants)
libpng/libpng 1.6.1 (2 CPE variants)
libpng/libpng 1.6.2 (2 CPE variants)
libpng/libpng 1.6.3 (2 CPE variants)
libpng/libpng 1.6.4 (2 CPE variants)
libpng/libpng 1.6.5
libpng/libpng 1.6.6
libpng/libpng 1.6.7 (2 CPE variants)
libpng/libpng 1.6.8 (2 CPE variants)
... and 9 more
Published Jan 18, 2015
Tracked Since Feb 18, 2026