Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libpng | Aug 30, 2017 | Jan 10, 2015 |
| Apple Osx Python | — | Upgrade macOS to the latest versionApply OS X security update 2016-002 | Mar 29, 2016 | Jan 18, 2015 |
| Debian | — | Upgrade libpng1.6Upgrade texlive-bin | Jul 30, 2024 | Jan 18, 2015 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libpngUpgrade libpng-devel | Jun 17, 2020 | Jan 18, 2015 |
| Oracle Solaris | — | Upgrade consolidation/desktop/desktop-incorporation to version 0.5.11-0.175.3.0.0.28.0 on Solaris 11.3Upgrade image/library/libpng to version 1.4.11-0.175.2.13.0.3.0 on Solaris 11.2 | May 29, 2017 | Jan 18, 2015 |
| Suse | — | Upgrade libpng16-16-32bitUpgrade libpng12-0Upgrade libpng16-16Upgrade libpng16-develUpgrade libpng16-compat-develUpgrade libpng12-devel | Dec 18, 2015 | Jan 18, 2015 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 18, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub