CVE-2015-8540

HIGH

libpng <1.0.66-1.2.56-1.3.19-1.4.19-1.5.26 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.

References (19)

Core 19
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201611-08
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/12/11/2
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2016:1430
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/12/10/6
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/12/11/1
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/12/10/7
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3443
Product x_refsource_confirm
http://sourceforge.net/p/libpng/bugs/244/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/80592
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/12/17/10
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174435.html

Scores

CVSS v3 8.8
EPSS 0.0643
EPSS Percentile 93.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-189
Status published
Products (48)
debian/debian_linux 6.0
fedoraproject/fedora 23
libpng/libpng 1.2.0
libpng/libpng 1.2.1
libpng/libpng 1.2.2
libpng/libpng 1.2.3
libpng/libpng 1.2.4
libpng/libpng 1.2.5
libpng/libpng 1.2.6
libpng/libpng 1.2.7
... and 38 more
Published Apr 14, 2016
Tracked Since Feb 18, 2026