CVE-2015-8540
published 2016-04-14CVE-2015-8540: Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and…
PriorityP346high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
6.43%
93.0th percentile
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.
Affected
181 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
| libpng | libpng | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libpng vulnerabilities
vendor_ubuntu·2016-01-06·CVSS 7.3
CVE-2015-8472 [HIGH] libpng vulnerabilities
Title: libpng vulnerabilities
Summary: libpng could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that libpng incorrectly handled certain small bit-depth
values. If a user or automated system using libpng were tricked into
opening a specially crafted image, an attacker could exploit this to cause
a denial of service or execute code with the privileges of the user
invoking the program. (CVE-2015-8472)
Qixue Xiao and Chen Yu discovered that libpng incorrectly handled certain
malformed images. If a user or automated system using libpng were tricked
into opening a specially crafted image, an attacker could exploit this to
cause a denial of service. (CVE-2015-8540)
Instructions: After a standard system update you need to restart your
Red Hat
libpng: underflow read in png_check_keyword()
vendor_redhat·2015-12-10·CVSS 8.8
CVE-2015-8540 [HIGH] CWE-125 libpng: underflow read in png_check_keyword()
libpng: underflow read in png_check_keyword()
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.
Package: libpng (Red Hat Enterprise Linux 5) - Will not fix
Package: libpng (Red Hat Enterprise Linux 6) - Will not fix
Package: libpng (Red Hat Enterprise Linux 7) - Will not fix
Package: libpng12 (Red Hat Enterprise Linux 7) - Will not fix
Package: libpng (Red Hat Enterprise Linux 8) - Not affected
Package: libpng12 (Red Hat Enterprise Linux 8) - Will not fix
Package: libpng15 (Red Hat Enterprise Li
GHSA
GHSA-7qhq-6293-wrx3: Integer underflow in the png_check_keyword function in pngwutil
ghsa_unreviewed·2022-05-13
CVE-2015-8540 [HIGH] GHSA-7qhq-6293-wrx3: Integer underflow in the png_check_keyword function in pngwutil
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.
OSV
libpng vulnerabilities
osv·2016-01-06·CVSS 7.3
CVE-2015-8472 [HIGH] libpng vulnerabilities
libpng vulnerabilities
It was discovered that libpng incorrectly handled certain small bit-depth
values. If a user or automated system using libpng were tricked into
opening a specially crafted image, an attacker could exploit this to cause
a denial of service or execute code with the privileges of the user
invoking the program. (CVE-2015-8472)
Qixue Xiao and Chen Yu discovered that libpng incorrectly handled certain
malformed images. If a user or automated system using libpng were tricked
into opening a specially crafted image, an attacker could exploit this to
cause a denial of service. (CVE-2015-8540)
OSV
CVE-2015-8540: Integer underflow in the png_check_keyword function in pngwutil
osv·2015-12-11·CVSS 8.8
CVE-2015-8540 [HIGH] CVE-2015-8540: Integer underflow in the png_check_keyword function in pngwutil
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8540 mingw-libpng: libpng: underflow read in png_check_keyword() [epel-7]
bugzilla·2015-12-14·CVSS 8.8
CVE-2015-8540 [HIGH] CVE-2015-8540 mingw-libpng: libpng: underflow read in png_check_keyword() [epel-7]
CVE-2015-8540 mingw-libpng: libpng: underflow read in png_check_keyword() [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for mingw-libpng: see bloc
Bugzilla
CVE-2015-8540 libpng10: libpng: underflow read in png_check_keyword() [fedora-all]
bugzilla·2015-12-14·CVSS 8.8
CVE-2015-8540 [HIGH] CVE-2015-8540 libpng10: libpng: underflow read in png_check_keyword() [fedora-all]
CVE-2015-8540 libpng10: libpng: underflow read in png_check_keyword() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2015-8540 libpng12: libpng: underflow read in png_check_keyword() [fedora-all]
bugzilla·2015-12-14·CVSS 8.8
CVE-2015-8540 [HIGH] CVE-2015-8540 libpng12: libpng: underflow read in png_check_keyword() [fedora-all]
CVE-2015-8540 libpng12: libpng: underflow read in png_check_keyword() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2015-8540 libpng10: libpng: underflow read in png_check_keyword() [epel-6]
bugzilla·2015-12-14·CVSS 8.8
CVE-2015-8540 [HIGH] CVE-2015-8540 libpng10: libpng: underflow read in png_check_keyword() [epel-6]
CVE-2015-8540 libpng10: libpng: underflow read in png_check_keyword() [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-6 tracking bug for libpng10: see blocks bug l
Bugzilla
CVE-2015-8540 mingw-libpng: libpng: underflow read in png_check_keyword() [fedora-all]
bugzilla·2015-12-14·CVSS 8.8
CVE-2015-8540 [HIGH] CVE-2015-8540 mingw-libpng: libpng: underflow read in png_check_keyword() [fedora-all]
CVE-2015-8540 mingw-libpng: libpng: underflow read in png_check_keyword() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2015-8540 libpng15: libpng: underflow read in png_check_keyword() [fedora-all]
bugzilla·2015-12-14·CVSS 8.8
CVE-2015-8540 [HIGH] CVE-2015-8540 libpng15: libpng: underflow read in png_check_keyword() [fedora-all]
CVE-2015-8540 libpng15: libpng: underflow read in png_check_keyword() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2015-8540 libpng: underflow read in png_check_keyword()
bugzilla·2015-12-14·CVSS 8.8
CVE-2015-8540 [HIGH] CVE-2015-8540 libpng: underflow read in png_check_keyword()
CVE-2015-8540 libpng: underflow read in png_check_keyword()
An underflow read was found in png_check_keyword in pngwutil.c in libpng-1.2.54:
If the data of "key" is only ' ' (0x20), it will read a byte before the buffer in line 1288.
This issue impacts upstream versions 1.2.55, 1.0.65, 1.4.18, and 1.5.25 of libpng.
An attacker could possibly use this flaw to cause an out-of-bounds read by tricking an unsuspecting user into processing a specially crafted PNG image.
CVE assignment:
http://seclists.org/oss-sec/2015/q4/469
Upstream issue:
http://sourceforge.net/p/libpng/bugs/244/
Upstream patch:
http://sourceforge.net/p/libpng/code/ci/d9006f683c641793252d92254a75ae9b815b42ed/
Discussion:
Created libpng tracking bugs for this issue:
Affects: fedora-all [bug 1291314]
---
Created l
Bugzilla
CVE-2015-8540 libpng: underflow read in png_check_keyword() [fedora-all]
bugzilla·2015-12-14·CVSS 8.8
CVE-2015-8540 [HIGH] CVE-2015-8540 libpng: underflow read in png_check_keyword() [fedora-all]
CVE-2015-8540 libpng: underflow read in png_check_keyword() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
arXiv
Match & Mend: Minimally Invasive Local Reassembly for Patching N-day Vulnerabilities in ARM Binaries
arxiv_fulltext·2025-10-16
Match & Mend: Minimally Invasive Local Reassembly for Patching N-day Vulnerabilities in ARM Binaries
expansion=sloppyMatch\,&\,Mend: Minimally Invasive Local Reassembly for Patching N-day Vulnerabilities in ARM Binaries
Sebastian Jänich
LMU Munich, Germany
[email protected]
Merlin Sievers
LMU Munich, Germany
[email protected]
Johannes Kinder
LMU Munich, Germany
[email protected]
* [1] #1
[1]
[colback=yellow!30, colframe=yellow!30, boxrule=0mm, arc=0mm, boxsep=0.5mm]#1
definitionDefinition
## Abstract
Low-cost Internet of Things (IoT) devices are increasingly popular but often insecure due to poor update regimes. As a result, many devices run outdated and known-vulnerable versions of open-source software.
We address this problem by proposing to patch IoT firmware at the binary level, without requiring vendor support. In particular, we introduce minimally invas
http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174435.htmlhttp://sourceforge.net/p/libpng/bugs/244/http://sourceforge.net/p/libpng/code/ci/d9006f683c641793252d92254a75ae9b815b42ed/http://sourceforge.net/projects/libpng/files/libpng10/1.0.66/http://sourceforge.net/projects/libpng/files/libpng12/1.2.56/http://sourceforge.net/projects/libpng/files/libpng14/1.4.19/http://sourceforge.net/projects/libpng/files/libpng15/1.5.26/http://www.debian.org/security/2016/dsa-3443http://www.openwall.com/lists/oss-security/2015/12/10/6http://www.openwall.com/lists/oss-security/2015/12/10/7http://www.openwall.com/lists/oss-security/2015/12/11/1http://www.openwall.com/lists/oss-security/2015/12/11/2http://www.openwall.com/lists/oss-security/2015/12/17/10http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/80592https://access.redhat.com/errata/RHSA-2016:1430https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://security.gentoo.org/glsa/201611-08http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174435.htmlhttp://sourceforge.net/p/libpng/bugs/244/http://sourceforge.net/p/libpng/code/ci/d9006f683c641793252d92254a75ae9b815b42ed/http://sourceforge.net/projects/libpng/files/libpng10/1.0.66/http://sourceforge.net/projects/libpng/files/libpng12/1.2.56/http://sourceforge.net/projects/libpng/files/libpng14/1.4.19/http://sourceforge.net/projects/libpng/files/libpng15/1.5.26/http://www.debian.org/security/2016/dsa-3443http://www.openwall.com/lists/oss-security/2015/12/10/6http://www.openwall.com/lists/oss-security/2015/12/10/7http://www.openwall.com/lists/oss-security/2015/12/11/1http://www.openwall.com/lists/oss-security/2015/12/11/2http://www.openwall.com/lists/oss-security/2015/12/17/10http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/80592https://access.redhat.com/errata/RHSA-2016:1430https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://security.gentoo.org/glsa/201611-08
2016-04-14
Published