7.5

CVE-2015-8126

Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libpng ≫ Libpng Version < 1.0.64
Libpng ≫ Libpng Version >= 1.1.1 < 1.2.54
Libpng ≫ Libpng Version >= 1.3.0 < 1.4.17
Libpng ≫ Libpng Version >= 1.5.0 < 1.5.24
Libpng ≫ Libpng Version >= 1.6.0 < 1.6.19
Fedoraproject ≫ Fedora Version 21
Fedoraproject ≫ Fedora Version 22
Fedoraproject ≫ Fedora Version 23
Opensuse ≫ Leap Version 42.1
Opensuse ≫ Opensuse Version 13.1
Opensuse ≫ Opensuse Version 13.2
Suse ≫ Linux Enterprise Desktop Version 11 Update sp3
Suse ≫ Linux Enterprise Desktop Version 11 Update sp4
Suse ≫ Linux Enterprise Desktop Version 12 Update -
Suse ≫ Linux Enterprise Desktop Version 12 Update sp1
Suse ≫ Linux Enterprise Server Version 12 Update -
Suse ≫ Linux Enterprise Server Version 12 Update sp1
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Redhat ≫ Satellite Version 5.7
Redhat ≫ Enterprise Linux Eus Version 6.7
Redhat ≫ Enterprise Linux Eus Version 7.2
Redhat ≫ Enterprise Linux Eus Version 7.3
Redhat ≫ Enterprise Linux Eus Version 7.4
Redhat ≫ Enterprise Linux Eus Version 7.5
Redhat ≫ Enterprise Linux Eus Version 7.6
Redhat ≫ Enterprise Linux Eus Version 7.7
Redhat ≫ Satellite Version 5.6
   Redhat ≫ Enterprise Linux Version 5.0
   Redhat ≫ Enterprise Linux Version 6.0
Oracle ≫ Jdk Version 1.6.0 Update update105
Oracle ≫ Jdk Version 1.7.0 Update update91
Oracle ≫ Jdk Version 1.8.0 Update update65
Oracle ≫ Jdk Version 1.8.0 Update update66
Oracle ≫ Jre Version 1.6.0 Update update105
Oracle ≫ Jre Version 1.7.0 Update update91
Oracle ≫ Jre Version 1.8.0 Update update65
Oracle ≫ Jre Version 1.8.0 Update update66
Oracle ≫ Linux Version 6 Update -
Oracle ≫ Linux Version 7 Update -
Oracle ≫ Solaris Version 11.3
Apple ≫ macOS X Version < 10.11.4
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 15.04
Canonical ≫ Ubuntu Linux Version 15.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.34% 0.951
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
Third Party Advisory
http://www.ubuntu.com/usn/USN-2815-1
Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
Third Party Advisory
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
Third Party Advisory
http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html
Third Party Advisory
Mailing List
https://support.apple.com/HT206167
Third Party Advisory
https://security.gentoo.org/glsa/201603-09
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html
Third Party Advisory
Mailing List
https://access.redhat.com/errata/RHSA-2016:1430
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.html
Third Party Advisory
Mailing List
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172324.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172620.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172647.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172663.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172769.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172797.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172823.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177344.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177382.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174905.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174936.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175073.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00033.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00034.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00041.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-updates/2015-11/msg00159.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-updates/2015-11/msg00160.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-updates/2015-12/msg00062.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-updates/2015-12/msg00063.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-updates/2016-01/msg00028.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-updates/2016-01/msg00029.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-updates/2016-01/msg00030.html
Third Party Advisory
Mailing List
http://rhn.redhat.com/errata/RHSA-2015-2594.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2595.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2596.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0055.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0056.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0057.html
Third Party Advisory
http://www.debian.org/security/2015/dsa-3399
Third Party Advisory
http://www.debian.org/security/2016/dsa-3507
Third Party Advisory
http://www.openwall.com/lists/oss-security/2015/11/12/2
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/77568
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1034142
Third Party Advisory
VDB Entry
https://code.google.com/p/chromium/issues/detail?id=560291
Patch
Third Party Advisory
Issue Tracking
https://kc.mcafee.com/corporate/index?page=content&id=SB10148
Third Party Advisory
https://security.gentoo.org/glsa/201611-08
Third Party Advisory