Buffer overflow in libpng - CVE-2015-8126
Published: November 13, 2015 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.
Affected software
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
Fedora
Slackware Linux
openEuler
libpng (Alpine package)
libpng10
libpng
libpng12
libpng15
libpng15-15-debuginfo
libpng15-debugsource
libpng15-15
mingw-libpng
media-libs/libpng
syslinux-debuginfo
syslinux
syslinux-extlinux-nonlinux
syslinux-nonlinux
syslinux-tftpboot
syslinux-debugsource
syslinux-devel
syslinux-efi64
syslinux-extlinux
syslinux-perl
IBM Integrated Management Module
Integrated Management Module II (IMM2)
GeForce driver for Linux
How to mitigate CVE-2015-8126
libpng (Alpine package) - update to 1.6.19-r0
IBM Integrated Management Module - update to YUOOH2B-1.5.1
Integrated Management Module II (IMM2) - update to 1aoo72h-5.60
libpng10 - addressed in versions 1.0.64-1.el6, 1.0.64-1.fc21, 1.0.64-1.fc22, 1.0.64-1.fc23, 1.0.65-1.el6, 1.0.65-1.fc22, 1.0.65-1.fc23, 1.0.66-1.el6
libpng - addressed in versions 1.2.54, 1.4.17
libpng12 - addressed in versions 1.2.56-1.fc22, 1.2.56-1.fc23
libpng15 - addressed in versions 1.5.21-2.fc22, 1.5.22-3.fc23, 1.5.25-1.fc22, 1.5.25-1.fc23
libpng15-15-debuginfo - update to 1.5.30-10.13.1
libpng15-debugsource - update to 1.5.30-10.13.1
libpng15-15 - update to 1.5.30-10.13.1
libpng - addressed in versions 1.6.16-4.fc22, 1.6.16-5.fc22, 1.6.17-3.fc23, 1.6.17-4.fc23
mingw-libpng - addressed in versions 1.6.19-1.fc21, 1.6.19-1.fc22, 1.6.19-1.fc23, 1.6.21-1.el7, 1.6.21-1.fc22, 1.6.21-1.fc23
media-libs/libpng - update to 1.6.21
syslinux-debuginfo - update to 6.04-16
syslinux - update to 6.04-16
syslinux-extlinux-nonlinux - update to 6.04-16
syslinux-nonlinux - update to 6.04-16
syslinux-tftpboot - update to 6.04-16
syslinux-debugsource - update to 6.04-16
syslinux-devel - update to 6.04-16
syslinux-efi64 - update to 6.04-16
syslinux-extlinux - update to 6.04-16
syslinux-perl - update to 6.04-16
GeForce driver for Linux - update to 367.27
External References
- http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172324.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172620.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172647.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172663.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172769.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172797.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172823.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177344.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177382.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174905.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174936.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175073.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00033.html
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00034.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00041.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.html
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00159.html
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00160.html
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00062.html
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00063.html
- http://lists.opensuse.org/opensuse-updates/2016-01/msg00028.html
- http://lists.opensuse.org/opensuse-updates/2016-01/msg00029.html
- http://lists.opensuse.org/opensuse-updates/2016-01/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2015-2594.html
- http://rhn.redhat.com/errata/RHSA-2015-2595.html
- http://rhn.redhat.com/errata/RHSA-2015-2596.html
- http://rhn.redhat.com/errata/RHSA-2016-0055.html
- http://rhn.redhat.com/errata/RHSA-2016-0056.html
- http://rhn.redhat.com/errata/RHSA-2016-0057.html
- http://www.debian.org/security/2015/dsa-3399
- http://www.debian.org/security/2016/dsa-3507
- http://www.openwall.com/lists/oss-security/2015/11/12/2
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.securityfocus.com/bid/77568
- http://www.securitytracker.com/id/1034142
- http://www.ubuntu.com/usn/USN-2815-1
- https://access.redhat.com/errata/RHSA-2016:1430
- https://code.google.com/p/chromium/issues/detail?id=560291
- https://kc.mcafee.com/corporate/index?page=content&id=SB10148
- https://security.gentoo.org/glsa/201603-09
- https://security.gentoo.org/glsa/201611-08
- https://support.apple.com/HT206167
Related Security Bulletins
- Buffer overflow in libpng
- Buffer overflow in libpng (Alpine package)
- Amazon Linux AMI update for libpng
- Slackware Linux update for libpng
- Multiple vulnerabilities in IBM Integrated Management Module (IMM)
- Multiple vulnerabilities in IBM Integrated Management Module II (IMM2) for System x, Flex and BladeCenter systems
- Multiple vulnerabilities in NVIDIA Linux device drivers for System x, Flex and BladeCenter Systems
- openEuler update for syslinux
- Gentoo update for libpng
- Slackware Linux update for libpng
- Fedora 21 update for libpng10
- Fedora 22 update for libpng10
- Fedora 23 update for libpng10
- Fedora EPEL 6 update for libpng10
- Fedora 23 update for libpng
- Fedora 22 update for libpng
- Fedora 23 update for libpng
- Fedora 22 update for libpng
- Fedora 23 update for libpng15
- Fedora 22 update for libpng15
- Fedora 22 update for mingw-libpng
- Fedora 23 update for mingw-libpng
- Fedora 21 update for mingw-libpng
- Fedora EPEL 6 update for libpng10
- Fedora 22 update for libpng10
- Fedora 23 update for libpng10
- Fedora 23 update for libpng15
- Fedora 22 update for libpng15
- Fedora EPEL 6 update for libpng10
- Fedora 23 update for libpng12
- Fedora 22 update for libpng12
- Fedora 23 update for mingw-libpng
- Fedora 22 update for mingw-libpng
- Fedora EPEL 7 update for mingw-libpng
- SUSE update for libpng15