5
CVE-2015-7981
- EPSS 6.36%
- Veröffentlicht 24.11.2015 20:59:15
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which triggers an out-of-bounds read.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 15.04
Canonical ≫ Ubuntu Linux Version 15.10
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Hpc Node Version 7.0
Redhat ≫ Enterprise Linux Hpc Node Eus Version 7.2
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 7.2
Redhat ≫ Enterprise Linux Server Eus Version 7.2
Redhat ≫ Enterprise Linux Workstation Version 7.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Hpc Node Version 6.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Eus Version 6.7.z
Redhat ≫ Enterprise Linux Workstation Version 6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.36% | 0.928 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
http://www.ubuntu.com/usn/USN-2815-1
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
https://access.redhat.com/errata/RHSA-2016:1430
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172620.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172647.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172663.html
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00033.html
http://lists.opensuse.org/opensuse-updates/2015-11/msg00160.html
http://rhn.redhat.com/errata/RHSA-2015-2594.html
http://rhn.redhat.com/errata/RHSA-2015-2595.html
http://www.debian.org/security/2015/dsa-3399
https://security.gentoo.org/glsa/201611-08
http://sourceforge.net/p/libpng/bugs/241/
http://sourceforge.net/projects/libpng/files/libpng10/1.0.64/
http://sourceforge.net/projects/libpng/files/libpng12/1.2.54/
http://sourceforge.net/projects/libpng/files/libpng14/1.4.17/
http://www.openwall.com/lists/oss-security/2015/10/26/1
http://www.openwall.com/lists/oss-security/2015/10/26/3
http://www.securityfocus.com/bid/77304
http://www.securitytracker.com/id/1034393