CVE-2015-7801Use After Free in Project Optipng

CWE-416Use After Free9 documents8 sources
Severity
8.8HIGHNVD
EPSS
2.4%
top 14.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 20
Latest updateMay 14

Description

Use-after-free vulnerability in OptiPNG 0.6.4 allows remote attackers to execute arbitrary code via a crafted PNG file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

Debianoptipng_project/optipng< 0.7.5-1+3
Ubuntuoptipng_project/optipng< 0.6.4-1ubuntu0.14.04.1

Also affects: Ubuntu Linux 12.04, 14.04, 15.10

🔴Vulnerability Details

4
GHSA
GHSA-76wm-4p7c-3hw9: Use-after-free vulnerability in OptiPNG 02022-05-14
OSV
CVE-2015-7801: Use-after-free vulnerability in OptiPNG 02016-04-20
CVEList
CVE-2015-7801: Use-after-free vulnerability in OptiPNG 02016-04-20
OSV
optipng vulnerabilities2016-04-18

📋Vendor Advisories

3
Ubuntu
OptiPNG vulnerabilities2016-04-18
Red Hat
optipng: Use-after-free vulnerability in 0.6.42015-09-16
Debian
CVE-2015-7801: optipng - Use-after-free vulnerability in OptiPNG 0.6.4 allows remote attackers to execute...2015

💬Community

1
Bugzilla
CVE-2015-7801 optipng: Use-after-free vulnerability in 0.6.42015-09-17
CVE-2015-7801 — Use After Free in Project Optipng | cvebase