Debian Pngcrush vulnerabilities
2 known vulnerabilities affecting debian/pngcrush.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1LOW1
Vulnerabilities
Page 1 of 1
CVE-2015-7700CRITICALCVSS 9.8fixed in pngcrush 1.8.13-0.1 (bookworm)2015
CVE-2015-7700 [CRITICAL] CVE-2015-7700: pngcrush - Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush befo...
Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors.
Scope: local
bookworm: resolved (fixed in 1.8.13-0.1)
bullseye: resolved (fixed in 1.8.13-0.1)
forky: resolved (fixed in 1.8.13-0.1)
sid: resolved (fixed in 1.8.13-0.1)
trixie: resolved (fixed in 1.8.13-0.1)
debian
CVE-2015-2158LOWCVSS 7.82015
CVE-2015-2158 [HIGH] CVE-2015-2158: pngcrush - Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush...
Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian