Input validation error in libpng - CVE-2015-8472
Published: January 21, 2016 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.
Affected software
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
Fedora
Slackware Linux
openEuler
libpng (Alpine package)
libpng10
libpng12
libpng15
libpng15-15-debuginfo
libpng15-debugsource
libpng15-15
libpng
mingw-libpng
syslinux-debuginfo
syslinux
syslinux-extlinux-nonlinux
syslinux-nonlinux
syslinux-tftpboot
syslinux-debugsource
syslinux-devel
syslinux-efi64
syslinux-extlinux
syslinux-perl
IBM Tivoli Storage Manager
GeForce driver for Linux
How to mitigate CVE-2015-8472
libpng (Alpine package) - update to 1.6.20-r0
libpng10 - addressed in versions 1.0.64-1.el6, 1.0.64-1.fc21, 1.0.64-1.fc22, 1.0.64-1.fc23, 1.0.65-1.el6, 1.0.65-1.fc22, 1.0.65-1.fc23, 1.0.66-1.el6
libpng12 - addressed in versions 1.2.56-1.fc22, 1.2.56-1.fc23
libpng15 - addressed in versions 1.5.21-2.fc22, 1.5.22-3.fc23, 1.5.25-1.fc22, 1.5.25-1.fc23
libpng15-15-debuginfo - update to 1.5.30-10.13.1
libpng15-debugsource - update to 1.5.30-10.13.1
libpng15-15 - update to 1.5.30-10.13.1
libpng - addressed in versions 1.6.16-4.fc22, 1.6.16-5.fc22, 1.6.17-3.fc23, 1.6.17-4.fc23
mingw-libpng - addressed in versions 1.6.19-1.fc21, 1.6.19-1.fc22, 1.6.19-1.fc23
IBM Tivoli Storage Manager - update to 6.3.1.2
syslinux-debuginfo - update to 6.04-16
syslinux - update to 6.04-16
syslinux-extlinux-nonlinux - update to 6.04-16
syslinux-nonlinux - update to 6.04-16
syslinux-tftpboot - update to 6.04-16
syslinux-debugsource - update to 6.04-16
syslinux-devel - update to 6.04-16
syslinux-efi64 - update to 6.04-16
syslinux-extlinux - update to 6.04-16
syslinux-perl - update to 6.04-16
GeForce driver for Linux - update to 367.27
External References
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174905.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174936.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175073.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00041.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.html
- http://rhn.redhat.com/errata/RHSA-2015-2594.html
- http://rhn.redhat.com/errata/RHSA-2015-2595.html
- http://rhn.redhat.com/errata/RHSA-2015-2596.html
- http://rhn.redhat.com/errata/RHSA-2016-0055.html
- http://rhn.redhat.com/errata/RHSA-2016-0056.html
- http://rhn.redhat.com/errata/RHSA-2016-0057.html
- http://sourceforge.net/projects/libpng/files/libpng10/1.0.65/
- http://sourceforge.net/projects/libpng/files/libpng12/1.2.55/
- http://sourceforge.net/projects/libpng/files/libpng14/1.4.18/
- http://sourceforge.net/projects/libpng/files/libpng15/1.5.25/
- http://sourceforge.net/projects/libpng/files/libpng16/1.6.20/
- http://www.debian.org/security/2016/dsa-3443
- http://www.openwall.com/lists/oss-security/2015/12/03/6
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.securityfocus.com/bid/78624
- https://access.redhat.com/errata/RHSA-2016:1430
- https://kc.mcafee.com/corporate/index?page=content&id=SB10148
- https://support.apple.com/HT206167
Related Security Bulletins
- Input validation error in libpng
- Input validation error in libpng (Alpine package)
- Slackware Linux update for libpng
- Multiple vulnerabilities in NVIDIA Linux device drivers for System x, Flex and BladeCenter Systems
- openEuler update for syslinux
- Fedora 21 update for libpng10
- Fedora 22 update for libpng10
- Fedora 23 update for libpng10
- Fedora EPEL 6 update for libpng10
- Fedora 23 update for libpng
- Fedora 22 update for libpng
- Fedora 23 update for libpng
- Fedora 22 update for libpng
- Fedora 23 update for libpng15
- Fedora 22 update for libpng15
- Fedora 22 update for mingw-libpng
- Fedora 23 update for mingw-libpng
- Fedora 21 update for mingw-libpng
- Fedora EPEL 6 update for libpng10
- Fedora 22 update for libpng10
- Fedora 23 update for libpng10
- Fedora 23 update for libpng15
- Fedora 22 update for libpng15
- Fedora EPEL 6 update for libpng10
- Fedora 23 update for libpng12
- Fedora 22 update for libpng12
- SUSE update for libpng15