Buffer overflow in libpng - CVE-2015-8126

 

Buffer overflow in libpng - CVE-2015-8126

Published: November 13, 2015 / Updated: July 28, 2020


Vulnerability identifier: #VU32378
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-8126
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.


Affected software

libpng
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
Fedora
Slackware Linux
openEuler
libpng (Alpine package)
libpng10
libpng
libpng12
libpng15
libpng15-15-debuginfo
libpng15-debugsource
libpng15-15
mingw-libpng
media-libs/libpng
syslinux-debuginfo
syslinux
syslinux-extlinux-nonlinux
syslinux-nonlinux
syslinux-tftpboot
syslinux-debugsource
syslinux-devel
syslinux-efi64
syslinux-extlinux
syslinux-perl
IBM Integrated Management Module
Integrated Management Module II (IMM2)
GeForce driver for Linux

How to mitigate CVE-2015-8126

Install update from vendor's website.

libpng - addressed in versions 1.0.64, 1.2.54, 1.4.17, 1.5.24, 1.6.19
libpng (Alpine package) - update to 1.6.19-r0
IBM Integrated Management Module - update to YUOOH2B-1.5.1
Integrated Management Module II (IMM2) - update to 1aoo72h-5.60
libpng10 - addressed in versions 1.0.64-1.el6, 1.0.64-1.fc21, 1.0.64-1.fc22, 1.0.64-1.fc23, 1.0.65-1.el6, 1.0.65-1.fc22, 1.0.65-1.fc23, 1.0.66-1.el6
libpng - addressed in versions 1.2.54, 1.4.17
libpng12 - addressed in versions 1.2.56-1.fc22, 1.2.56-1.fc23
libpng15 - addressed in versions 1.5.21-2.fc22, 1.5.22-3.fc23, 1.5.25-1.fc22, 1.5.25-1.fc23
libpng15-15-debuginfo - update to 1.5.30-10.13.1
libpng15-debugsource - update to 1.5.30-10.13.1
libpng15-15 - update to 1.5.30-10.13.1
libpng - addressed in versions 1.6.16-4.fc22, 1.6.16-5.fc22, 1.6.17-3.fc23, 1.6.17-4.fc23
mingw-libpng - addressed in versions 1.6.19-1.fc21, 1.6.19-1.fc22, 1.6.19-1.fc23, 1.6.21-1.el7, 1.6.21-1.fc22, 1.6.21-1.fc23
media-libs/libpng - update to 1.6.21
syslinux-debuginfo - update to 6.04-16
syslinux - update to 6.04-16
syslinux-extlinux-nonlinux - update to 6.04-16
syslinux-nonlinux - update to 6.04-16
syslinux-tftpboot - update to 6.04-16
syslinux-debugsource - update to 6.04-16
syslinux-devel - update to 6.04-16
syslinux-efi64 - update to 6.04-16
syslinux-extlinux - update to 6.04-16
syslinux-perl - update to 6.04-16
GeForce driver for Linux - update to 367.27

External References

Related Security Bulletins