CVE-2015-8126
published 2015-11-13CVE-2015-8126: Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
10.34%
95.2th percentile
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.
Affected
172 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.11.4 | 10.11.4 |
| apple | mac_os_x | <= 10.11.3 | — |
| apple | os_x_el_capitan_v10.11.4_and_security_update_2016-002 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libpng1.6 | < libpng1.6 1.6.20-1 (bookworm) | libpng1.6 1.6.20-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libpng | libpng | < 1.0.64 | 1.0.64 |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libpng vulnerabilities
vendor_ubuntu·2015-11-19·CVSS 4.3
CVE-2012-3425 [MEDIUM] libpng vulnerabilities
Title: libpng vulnerabilities
Summary: libpng could be made to crash or run programs as your login if it
opened a specially crafted file.
Mikulas Patocka discovered that libpng incorrectly handled certain large
fields. If a user or automated system using libpng were tricked into
opening a specially crafted image, an attacker could exploit this to cause
libpng to crash, leading to a denial of service. This issue only affected
Ubuntu 12.04 LTS. (CVE-2012-3425)
Qixue Xiao discovered that libpng incorrectly handled certain time values.
If a user or automated system using libpng were tricked into opening a
specially crafted image, an attacker could exploit this to cause libpng to
crash, leading to a denial of service. (CVE-2015-7981)
It was discovered that libpng incorrectly handled certain
Red Hat
libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions
vendor_redhat·2015-11-12·CVSS 7.5
CVE-2015-8472 [HIGH] CWE-120 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions
libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions
Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8126.
It was discovered that the png_get_PLTE() and png_set_PLTE() functions of libpng did not correctly calculate the maximum palette sizes for bit depths of less than 8. In case an application tried to use these functions in combination with properly calculated palette size
Red Hat
libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions
vendor_redhat·2015-11-12·CVSS 7.5
CVE-2015-8126 [HIGH] CWE-120 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions
libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.
It was discovered that the png_get_PLTE() and png_set_PLTE() functions of libpng did not correctly calculate the maximum palette sizes for bit depths of less than 8. In case an application tried to use these functions in combination with properly calculated palette sizes, this could lead to a buffer overflow or
Debian
CVE-2015-8472: libpng1.6 - Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and ...
vendor_debian·2015·CVSS 7.5
CVE-2015-8472 [HIGH] CVE-2015-8472: libpng1.6 - Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and ...
Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8126.
Scope: local
bookworm: resolved (fixed in 1.6.20-1)
bullseye: resolved (fixed in 1.6.20-1)
forky: resolved (fixed in 1.6.20-1)
sid: resolved (fixed in 1.6.20-1)
trixie: resolved (fixed in 1.6.20-1)
Apple
CVE-2015-8126: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 7.5
CVE-2015-8126 [HIGH] CVE-2015-8126: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2015-8126
Component: CVE-ID
GHSA
GHSA-h5hh-r95x-mmfq: Buffer overflow in the png_set_PLTE function in libpng before 1
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2015-8472 [HIGH] CWE-119 GHSA-h5hh-r95x-mmfq: Buffer overflow in the png_set_PLTE function in libpng before 1
Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8126.
GHSA
GHSA-rr6q-q2jh-948f: Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1
ghsa_unreviewed·2022-05-13
CVE-2015-8126 [HIGH] CWE-120 GHSA-rr6q-q2jh-948f: Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.
OSV
CVE-2015-8472: Buffer overflow in the png_set_PLTE function in libpng before 1
osv·2016-01-21·CVSS 7.5
CVE-2015-8472 [HIGH] CVE-2015-8472: Buffer overflow in the png_set_PLTE function in libpng before 1
Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8126.
OSV
libpng vulnerabilities
osv·2015-11-19·CVSS 4.3
CVE-2012-3425 [MEDIUM] libpng vulnerabilities
libpng vulnerabilities
Mikulas Patocka discovered that libpng incorrectly handled certain large
fields. If a user or automated system using libpng were tricked into
opening a specially crafted image, an attacker could exploit this to cause
libpng to crash, leading to a denial of service. This issue only affected
Ubuntu 12.04 LTS. (CVE-2012-3425)
Qixue Xiao discovered that libpng incorrectly handled certain time values.
If a user or automated system using libpng were tricked into opening a
specially crafted image, an attacker could exploit this to cause libpng to
crash, leading to a denial of service. (CVE-2015-7981)
It was discovered that libpng incorrectly handled certain small bit-depth
values. If a user or automated system using libpng were tricked into
opening a specially crafted im
OSV
CVE-2015-8126: Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1
osv·2015-11-12·CVSS 7.5
CVE-2015-8126 [HIGH] CVE-2015-8126: Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8126 libpng15: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [fedora-all]
bugzilla·2015-11-17·CVSS 7.5
CVE-2015-8126 [HIGH] CVE-2015-8126 libpng15: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [fedora-all]
CVE-2015-8126 libpng15: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2015-8126 libpng12: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [fedora-all]
bugzilla·2015-11-17·CVSS 7.5
CVE-2015-8126 [HIGH] CVE-2015-8126 libpng12: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [fedora-all]
CVE-2015-8126 libpng12: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2015-8126 libpng10: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [fedora-all]
bugzilla·2015-11-14·CVSS 7.5
CVE-2015-8126 [HIGH] CVE-2015-8126 libpng10: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [fedora-all]
CVE-2015-8126 libpng10: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [fedora-all]
Tracking bug for affected Fedora releases 21 .. 23.
Discussion:
libpng10-1.0.64-1.fc23 has been submitted as an update to Fedora 23. https://bodhi.fedoraproject.org/updates/FEDORA-2015-1d87313b7c
---
libpng10-1.0.64-1.fc22 has been submitted as an update to Fedora 22. https://bodhi.fedoraproject.org/updates/FEDORA-2015-ec2ddd15d7
---
libpng10-1.0.64-1.fc21 has been submitted as an update to Fedora 21. https://bodhi.fedoraproject.org/updates/FEDORA-2015-501493d853
---
libpng10-1.0.64-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
---
libpng10-1.0.64-1.fc22 has been pushed to the Fedora
Bugzilla
CVE-2015-8126 CVE-2015-8472 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions
bugzilla·2015-11-13·CVSS 7.5
CVE-2015-8126 [HIGH] CVE-2015-8126 CVE-2015-8472 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions
CVE-2015-8126 CVE-2015-8472 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions
Buffer overflow vulnerabilities in functions png_get_PLTE/png_set_PLTE, allowing remote attackers to cause DoS to application or have unspecified other impact. These functions failed to check for an out-of-range palette when reading or writing PNG files with a bit_depth less than 8. Some applications might read the bit depth from the IHDR chunk and allocate memory for a 2^N entry palette, while libpng can return a palette with up to 256 entries even when the bit depth is less than 8.
Affected versions of libpng are before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19.
Upstream patches:
https://github.com/glennrp/
Bugzilla
CVE-2015-8126 libpng10: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [epel-6]
bugzilla·2015-11-13·CVSS 7.5
CVE-2015-8126 [HIGH] CVE-2015-8126 libpng10: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [epel-6]
CVE-2015-8126 libpng10: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-6 tracking b
Bugzilla
CVE-2015-8126 mingw-libpng: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [epel-7]
bugzilla·2015-11-13·CVSS 7.5
CVE-2015-8126 [HIGH] CVE-2015-8126 mingw-libpng: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [epel-7]
CVE-2015-8126 mingw-libpng: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracki
Bugzilla
CVE-2015-8126 mingw-libpng: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [fedora-all]
bugzilla·2015-11-13·CVSS 7.5
CVE-2015-8126 [HIGH] CVE-2015-8126 mingw-libpng: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [fedora-all]
CVE-2015-8126 mingw-libpng: libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2015-8126 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [fedora-all]
bugzilla·2015-11-13·CVSS 7.5
CVE-2015-8126 [HIGH] CVE-2015-8126 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [fedora-all]
CVE-2015-8126 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172324.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172620.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172647.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172663.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172769.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172797.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172823.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177344.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177382.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/174905.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/174936.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175073.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00159.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00160.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00062.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00063.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00028.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00030.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2594.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2595.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2596.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0055.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0056.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0057.htmlhttp://www.debian.org/security/2015/dsa-3399http://www.debian.org/security/2016/dsa-3507http://www.openwall.com/lists/oss-security/2015/11/12/2http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/77568http://www.securitytracker.com/id/1034142http://www.ubuntu.com/usn/USN-2815-1https://access.redhat.com/errata/RHSA-2016:1430https://code.google.com/p/chromium/issues/detail?id=560291https://kc.mcafee.com/corporate/index?page=content&id=SB10148https://security.gentoo.org/glsa/201603-09https://security.gentoo.org/glsa/201611-08https://support.apple.com/HT206167http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172324.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172620.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172647.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172663.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172769.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172797.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172823.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177344.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177382.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/174905.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/174936.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175073.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00159.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00160.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00062.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00063.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00028.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00030.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2594.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2595.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2596.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0055.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0056.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0057.htmlhttp://www.debian.org/security/2015/dsa-3399http://www.debian.org/security/2016/dsa-3507http://www.openwall.com/lists/oss-security/2015/11/12/2
+ 12 more references
2015-11-13
Published