Integer underflow in libpng - CVE-2015-8540

 

Integer underflow in libpng - CVE-2015-8540

Published: September 10, 2024


Vulnerability identifier: #VU96992
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-8540
CWE-ID: CWE-191
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer underflow within the png_check_keyword() function in pngwutil.c. A remote attacker can trick the victim to open a specially crafted PNG file, trigger an integer underflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

libpng
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
Fedora
Slackware Linux
openEuler
libpng10
libpng
libpng12
libpng15-15
libpng15-debugsource
libpng15-15-debuginfo
media-libs/libpng
syslinux
syslinux-perl
syslinux-extlinux
syslinux-efi64
syslinux-devel
syslinux-debugsource
syslinux-debuginfo
syslinux-tftpboot
syslinux-nonlinux
syslinux-extlinux-nonlinux

How to mitigate CVE-2015-8540

Install updates from vendor's website.

libpng - addressed in versions 0.99, 1.0.66, 1.2.56, 1.4.19, 1.5.26
libpng10 - addressed in versions 1.0.66-1.el6, 1.0.66-1.fc22, 1.0.66-1.fc23
libpng - addressed in versions 1.2.56, 1.4.19
libpng12 - addressed in versions 1.2.56-1.fc22, 1.2.56-1.fc23
libpng15-15 - update to 1.5.30-10.13.1
libpng15-debugsource - update to 1.5.30-10.13.1
libpng15-15-debuginfo - update to 1.5.30-10.13.1
media-libs/libpng - update to 1.6.21
syslinux - update to 6.04-16
syslinux-perl - update to 6.04-16
syslinux-extlinux - update to 6.04-16
syslinux-efi64 - update to 6.04-16
syslinux-devel - update to 6.04-16
syslinux-debugsource - update to 6.04-16
syslinux-debuginfo - update to 6.04-16
syslinux-tftpboot - update to 6.04-16
syslinux-nonlinux - update to 6.04-16
syslinux-extlinux-nonlinux - update to 6.04-16

External References

Related Security Bulletins