CVE-2015-7700

CRITICAL

pngcrush <1.7.87 - Memory Corruption

Title source: llm

Description

Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors.

Scores

CVSS v3 9.8
EPSS 0.0069
EPSS Percentile 71.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-415
Status draft

Affected Products (1)

pngcrush_project/pngcrush < 1.7.86

Timeline

Published Aug 31, 2017
Tracked Since Feb 18, 2026