CVE-2015-8472
published 2016-01-21CVE-2015-8472: Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x…
PriorityP340high7.3CVSS 3.0
AVNACLPRNUINSUCLILAL
EPSS
6.05%
92.6th percentile
Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8126.
Affected
119 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.11.3 | — |
| apple | os_x_el_capitan_v10.11.4_and_security_update_2016-002 | — | — |
| debian | libpng1.6 | < libpng1.6 1.6.20-1 (bookworm) | libpng1.6 1.6.20-1 (bookworm) |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
CVSS provenance
nvdv3.07.3HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_msrc7.3HIGH
vendor_ubuntu7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Buffer overflow in libpng allows remote attackers to cause a denial of service
vendor_msrc·2016-01-12·CVSS 7.3
CVE-2015-8472 [HIGH] Buffer overflow in libpng allows remote attackers to cause a denial of service
Buffer overflow in libpng allows remote attackers to cause a denial of service
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
R
Ubuntu
libpng vulnerabilities
vendor_ubuntu·2016-01-06·CVSS 7.3
CVE-2015-8472 [HIGH] libpng vulnerabilities
Title: libpng vulnerabilities
Summary: libpng could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that libpng incorrectly handled certain small bit-depth
values. If a user or automated system using libpng were tricked into
opening a specially crafted image, an attacker could exploit this to cause
a denial of service or execute code with the privileges of the user
invoking the program. (CVE-2015-8472)
Qixue Xiao and Chen Yu discovered that libpng incorrectly handled certain
malformed images. If a user or automated system using libpng were tricked
into opening a specially crafted image, an attacker could exploit this to
cause a denial of service. (CVE-2015-8540)
Instructions: After a standard system update you need to restart your
Red Hat
libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions
vendor_redhat·2015-11-12·CVSS 7.5
CVE-2015-8472 [HIGH] CWE-120 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions
libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions
Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8126.
It was discovered that the png_get_PLTE() and png_set_PLTE() functions of libpng did not correctly calculate the maximum palette sizes for bit depths of less than 8. In case an application tried to use these functions in combination with properly calculated palette size
Debian
CVE-2015-8472: libpng1.6 - Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and ...
vendor_debian·2015·CVSS 7.5
CVE-2015-8472 [HIGH] CVE-2015-8472: libpng1.6 - Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and ...
Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8126.
Scope: local
bookworm: resolved (fixed in 1.6.20-1)
bullseye: resolved (fixed in 1.6.20-1)
forky: resolved (fixed in 1.6.20-1)
sid: resolved (fixed in 1.6.20-1)
trixie: resolved (fixed in 1.6.20-1)
Apple
CVE-2015-8472: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 7.3
CVE-2015-8472 [HIGH] CVE-2015-8472: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2015-8472
Component: CVE-ID
GHSA
GHSA-h5hh-r95x-mmfq: Buffer overflow in the png_set_PLTE function in libpng before 1
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2015-8472 [HIGH] CWE-119 GHSA-h5hh-r95x-mmfq: Buffer overflow in the png_set_PLTE function in libpng before 1
Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8126.
OSV
CVE-2015-8472: Buffer overflow in the png_set_PLTE function in libpng before 1
osv·2016-01-21·CVSS 7.5
CVE-2015-8472 [HIGH] CVE-2015-8472: Buffer overflow in the png_set_PLTE function in libpng before 1
Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8126.
OSV
libpng vulnerabilities
osv·2016-01-06·CVSS 7.3
CVE-2015-8472 [HIGH] libpng vulnerabilities
libpng vulnerabilities
It was discovered that libpng incorrectly handled certain small bit-depth
values. If a user or automated system using libpng were tricked into
opening a specially crafted image, an attacker could exploit this to cause
a denial of service or execute code with the privileges of the user
invoking the program. (CVE-2015-8472)
Qixue Xiao and Chen Yu discovered that libpng incorrectly handled certain
malformed images. If a user or automated system using libpng were tricked
into opening a specially crafted image, an attacker could exploit this to
cause a denial of service. (CVE-2015-8540)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8126 CVE-2015-8472 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions
bugzilla·2015-11-13·CVSS 7.5
CVE-2015-8126 [HIGH] CVE-2015-8126 CVE-2015-8472 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions
CVE-2015-8126 CVE-2015-8472 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions
Buffer overflow vulnerabilities in functions png_get_PLTE/png_set_PLTE, allowing remote attackers to cause DoS to application or have unspecified other impact. These functions failed to check for an out-of-range palette when reading or writing PNG files with a bit_depth less than 8. Some applications might read the bit depth from the IHDR chunk and allocate memory for a 2^N entry palette, while libpng can return a palette with up to 256 entries even when the bit depth is less than 8.
Affected versions of libpng are before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19.
Upstream patches:
https://github.com/glennrp/
arXiv
Magma: A Ground-Truth Fuzzing Benchmark
arxiv_fulltext·2020-10-23
Magma: A Ground-Truth Fuzzing Benchmark
: A Ground-Truth Fuzzing Benchmark
Ahmad Hazimeh
EPFLSwitzerland
[email protected]
Adrian Herrera
ANU & DSTAustralia
[email protected]
Mathias Payer
EPFLSwitzerland
[email protected]
## Abstract
High scalability and low running costs have made fuzz testing the de facto
standard for discovering software bugs. Fuzzing techniques are constantly being
improved in a race to build the ultimate bug-finding tool. However, while
fuzzing excels at finding bugs in the wild, evaluating and comparing fuzzer
performance is challenging due to the lack of metrics and benchmarks. For
example, crash count---perhaps the most commonly-used performance metric---is
inaccurate due to imperfections in deduplication techniques. Additionally, the
lack of a unified set of targets results in
http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/174905.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/174936.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175073.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2594.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2595.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2596.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0055.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0056.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0057.htmlhttp://sourceforge.net/projects/libpng/files/libpng10/1.0.65/http://sourceforge.net/projects/libpng/files/libpng12/1.2.55/http://sourceforge.net/projects/libpng/files/libpng14/1.4.18/http://sourceforge.net/projects/libpng/files/libpng15/1.5.25/http://sourceforge.net/projects/libpng/files/libpng16/1.6.20/http://www.debian.org/security/2016/dsa-3443http://www.openwall.com/lists/oss-security/2015/12/03/6http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/78624https://access.redhat.com/errata/RHSA-2016:1430https://kc.mcafee.com/corporate/index?page=content&id=SB10148https://support.apple.com/HT206167http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/174905.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/174936.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175073.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2594.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2595.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2596.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0055.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0056.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0057.htmlhttp://sourceforge.net/projects/libpng/files/libpng10/1.0.65/http://sourceforge.net/projects/libpng/files/libpng12/1.2.55/http://sourceforge.net/projects/libpng/files/libpng14/1.4.18/http://sourceforge.net/projects/libpng/files/libpng15/1.5.25/http://sourceforge.net/projects/libpng/files/libpng16/1.6.20/http://www.debian.org/security/2016/dsa-3443http://www.openwall.com/lists/oss-security/2015/12/03/6http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/78624https://access.redhat.com/errata/RHSA-2016:1430https://kc.mcafee.com/corporate/index?page=content&id=SB10148https://support.apple.com/HT206167
2016-01-21
Published