Input validation error in libpng - CVE-2015-8472

 

Input validation error in libpng - CVE-2015-8472

Published: January 21, 2016 / Updated: July 28, 2020


Vulnerability identifier: #VU32352
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-8472
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows remote attackers to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.


Affected software

libpng
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
Fedora
Slackware Linux
openEuler
libpng (Alpine package)
libpng10
libpng12
libpng15
libpng15-15-debuginfo
libpng15-debugsource
libpng15-15
libpng
mingw-libpng
syslinux-debuginfo
syslinux
syslinux-extlinux-nonlinux
syslinux-nonlinux
syslinux-tftpboot
syslinux-debugsource
syslinux-devel
syslinux-efi64
syslinux-extlinux
syslinux-perl
IBM Tivoli Storage Manager
GeForce driver for Linux

How to mitigate CVE-2015-8472

The vendor has issued the following versions to address this vulnerability: 1.0.65, 1.2.55, 1.4.18, 1.5.25, 1.6.20.

libpng - addressed in versions 1.0.65, 1.2.55, 1.4.18, 1.5.25, 1.6.20
libpng (Alpine package) - update to 1.6.20-r0
libpng10 - addressed in versions 1.0.64-1.el6, 1.0.64-1.fc21, 1.0.64-1.fc22, 1.0.64-1.fc23, 1.0.65-1.el6, 1.0.65-1.fc22, 1.0.65-1.fc23, 1.0.66-1.el6
libpng12 - addressed in versions 1.2.56-1.fc22, 1.2.56-1.fc23
libpng15 - addressed in versions 1.5.21-2.fc22, 1.5.22-3.fc23, 1.5.25-1.fc22, 1.5.25-1.fc23
libpng15-15-debuginfo - update to 1.5.30-10.13.1
libpng15-debugsource - update to 1.5.30-10.13.1
libpng15-15 - update to 1.5.30-10.13.1
libpng - addressed in versions 1.6.16-4.fc22, 1.6.16-5.fc22, 1.6.17-3.fc23, 1.6.17-4.fc23
mingw-libpng - addressed in versions 1.6.19-1.fc21, 1.6.19-1.fc22, 1.6.19-1.fc23
IBM Tivoli Storage Manager - update to 6.3.1.2
syslinux-debuginfo - update to 6.04-16
syslinux - update to 6.04-16
syslinux-extlinux-nonlinux - update to 6.04-16
syslinux-nonlinux - update to 6.04-16
syslinux-tftpboot - update to 6.04-16
syslinux-debugsource - update to 6.04-16
syslinux-devel - update to 6.04-16
syslinux-efi64 - update to 6.04-16
syslinux-extlinux - update to 6.04-16
syslinux-perl - update to 6.04-16
GeForce driver for Linux - update to 367.27

External References

Related Security Bulletins