CVE-2015-7981
published 2015-11-24CVE-2015-7981: The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain…
PriorityP429medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
6.36%
92.9th percentile
The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which triggers an out-of-bounds read.
Affected
151 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fr3h-2jww-582m: The png_convert_to_rfc1123 function in png
ghsa_unreviewed·2022-05-17
CVE-2015-7981 [MEDIUM] CWE-200 GHSA-fr3h-2jww-582m: The png_convert_to_rfc1123 function in png
The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which triggers an out-of-bounds read.
OSV
libpng vulnerabilities
osv·2015-11-19·CVSS 4.3
CVE-2012-3425 [MEDIUM] libpng vulnerabilities
libpng vulnerabilities
Mikulas Patocka discovered that libpng incorrectly handled certain large
fields. If a user or automated system using libpng were tricked into
opening a specially crafted image, an attacker could exploit this to cause
libpng to crash, leading to a denial of service. This issue only affected
Ubuntu 12.04 LTS. (CVE-2012-3425)
Qixue Xiao discovered that libpng incorrectly handled certain time values.
If a user or automated system using libpng were tricked into opening a
specially crafted image, an attacker could exploit this to cause libpng to
crash, leading to a denial of service. (CVE-2015-7981)
It was discovered that libpng incorrectly handled certain small bit-depth
values. If a user or automated system using libpng were tricked into
opening a specially crafted im
OSV
CVE-2015-7981: The png_convert_to_rfc1123 function in png
osv·2015-10-26·CVSS 5.0
CVE-2015-7981 [MEDIUM] CVE-2015-7981: The png_convert_to_rfc1123 function in png
The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which triggers an out-of-bounds read.
Ubuntu
libpng vulnerabilities
vendor_ubuntu·2015-11-19·CVSS 4.3
CVE-2012-3425 [MEDIUM] libpng vulnerabilities
Title: libpng vulnerabilities
Summary: libpng could be made to crash or run programs as your login if it
opened a specially crafted file.
Mikulas Patocka discovered that libpng incorrectly handled certain large
fields. If a user or automated system using libpng were tricked into
opening a specially crafted image, an attacker could exploit this to cause
libpng to crash, leading to a denial of service. This issue only affected
Ubuntu 12.04 LTS. (CVE-2012-3425)
Qixue Xiao discovered that libpng incorrectly handled certain time values.
If a user or automated system using libpng were tricked into opening a
specially crafted image, an attacker could exploit this to cause libpng to
crash, leading to a denial of service. (CVE-2015-7981)
It was discovered that libpng incorrectly handled certain
Red Hat
libpng: Out-of-bounds read in png_convert_to_rfc1123
vendor_redhat·2015-10-22·CVSS 5.0
CVE-2015-7981 [MEDIUM] CWE-125 libpng: Out-of-bounds read in png_convert_to_rfc1123
libpng: Out-of-bounds read in png_convert_to_rfc1123
The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which triggers an out-of-bounds read.
An array-indexing error was discovered in the png_convert_to_rfc1123() function of libpng. An attacker could possibly use this flaw to cause an out-of-bounds read by tricking an unsuspecting user into processing a specially crafted PNG image.
Package: libpng (Red Hat Enterprise Linux 4) - Will not fix
Package: libpng10 (Red Hat Enterprise Linux 4) - Will not fix
Package: libpng (Red Hat Enterprise Linux 5) - Will not fix
Package: libpng (Red Hat Enterprise Linu
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7981 libpng: Out-of-bounds read in png_convert_to_rfc1123
bugzilla·2015-10-29·CVSS 5.0
CVE-2015-7981 [MEDIUM] CVE-2015-7981 libpng: Out-of-bounds read in png_convert_to_rfc1123
CVE-2015-7981 libpng: Out-of-bounds read in png_convert_to_rfc1123
An out-of-bounds read in png_convert_to_rfc1123 in png.c was found.
Upstream bug:
http://sourceforge.net/p/libpng/bugs/241/
Upstream patch:
http://sourceforge.net/p/libpng/code/ci/fbf0f024346ca0a4ffc64b082a95c6b6bb6d29c4/
CVE assignment:
http://seclists.org/oss-sec/2015/q4/161
Discussion:
Created libpng10 tracking bugs for this issue:
Affects: fedora-all [bug 1276417]
Affects: epel-6 [bug 1276419]
---
Created libpng12 tracking bugs for this issue:
Affects: fedora-all [bug 1276418]
---
This is an array indexing error, which can lead to an out-of-bounds read of a static buffer.
The fix is strange, but should work: the result is now unsigned (no longer negative, but now a huge positive number). But that doesn't
Bugzilla
CVE-2015-7981 libpng12: libpng: Out-of-bounds read in png_convert_to_rfc1123 [fedora-all]
bugzilla·2015-10-29·CVSS 5.0
CVE-2015-7981 [MEDIUM] CVE-2015-7981 libpng12: libpng: Out-of-bounds read in png_convert_to_rfc1123 [fedora-all]
CVE-2015-7981 libpng12: libpng: Out-of-bounds read in png_convert_to_rfc1123 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2015-7981 libpng10: libpng: Out-of-bounds read in png_convert_to_rfc1123 [epel-6]
bugzilla·2015-10-29·CVSS 5.0
CVE-2015-7981 [MEDIUM] CVE-2015-7981 libpng10: libpng: Out-of-bounds read in png_convert_to_rfc1123 [epel-6]
CVE-2015-7981 libpng10: libpng: Out-of-bounds read in png_convert_to_rfc1123 [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-6 tracking bug for libpng10: see block
Bugzilla
CVE-2015-7981 libpng10: libpng: Out-of-bounds read in png_convert_to_rfc1123 [fedora-all]
bugzilla·2015-10-29·CVSS 5.0
CVE-2015-7981 [MEDIUM] CVE-2015-7981 libpng10: libpng: Out-of-bounds read in png_convert_to_rfc1123 [fedora-all]
CVE-2015-7981 libpng10: libpng: Out-of-bounds read in png_convert_to_rfc1123 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172620.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172647.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172663.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00033.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00160.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2594.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2595.htmlhttp://sourceforge.net/p/libpng/bugs/241/http://sourceforge.net/projects/libpng/files/libpng10/1.0.64/http://sourceforge.net/projects/libpng/files/libpng12/1.2.54/http://sourceforge.net/projects/libpng/files/libpng14/1.4.17/http://www.debian.org/security/2015/dsa-3399http://www.openwall.com/lists/oss-security/2015/10/26/1http://www.openwall.com/lists/oss-security/2015/10/26/3http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/77304http://www.securitytracker.com/id/1034393http://www.ubuntu.com/usn/USN-2815-1https://access.redhat.com/errata/RHSA-2016:1430https://security.gentoo.org/glsa/201611-08http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172620.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172647.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172663.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00033.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00160.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2594.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2595.htmlhttp://sourceforge.net/p/libpng/bugs/241/http://sourceforge.net/projects/libpng/files/libpng10/1.0.64/http://sourceforge.net/projects/libpng/files/libpng12/1.2.54/http://sourceforge.net/projects/libpng/files/libpng14/1.4.17/http://www.debian.org/security/2015/dsa-3399http://www.openwall.com/lists/oss-security/2015/10/26/1http://www.openwall.com/lists/oss-security/2015/10/26/3http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/77304http://www.securitytracker.com/id/1034393http://www.ubuntu.com/usn/USN-2815-1https://access.redhat.com/errata/RHSA-2016:1430https://security.gentoo.org/glsa/201611-08
2015-11-24
Published