CVE-2015-8472
Summary
| CVE | CVE-2015-8472 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-01-21 15:59:00 UTC |
| Updated | 2017-11-04 01:29:00 UTC |
| Description | Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8126. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | All | All | All | All |
| Application | Libpng | Libpng | 1.0.64 | All | All | All |
| Application | Libpng | Libpng | 1.2.0 | All | All | All |
| Application | Libpng | Libpng | 1.2.1 | All | All | All |
| Application | Libpng | Libpng | 1.2.10 | All | All | All |
| Application | Libpng | Libpng | 1.2.11 | All | All | All |
| Application | Libpng | Libpng | 1.2.12 | All | All | All |
| Application | Libpng | Libpng | 1.2.13 | All | All | All |
| Application | Libpng | Libpng | 1.2.14 | All | All | All |
| Application | Libpng | Libpng | 1.2.15 | All | All | All |
| Application | Libpng | Libpng | 1.2.16 | All | All | All |
| Application | Libpng | Libpng | 1.2.17 | All | All | All |
| Application | Libpng | Libpng | 1.2.18 | All | All | All |
| Application | Libpng | Libpng | 1.2.19 | All | All | All |
| Application | Libpng | Libpng | 1.2.2 | All | All | All |
| Application | Libpng | Libpng | 1.2.20 | All | All | All |
| Application | Libpng | Libpng | 1.2.21 | All | All | All |
| Application | Libpng | Libpng | 1.2.22 | All | All | All |
| Application | Libpng | Libpng | 1.2.23 | All | All | All |
| Application | Libpng | Libpng | 1.2.24 | All | All | All |
| Application | Libpng | Libpng | 1.2.25 | All | All | All |
| Application | Libpng | Libpng | 1.2.26 | All | All | All |
| Application | Libpng | Libpng | 1.2.27 | All | All | All |
| Application | Libpng | Libpng | 1.2.28 | All | All | All |
| Application | Libpng | Libpng | 1.2.29 | All | All | All |
| Application | Libpng | Libpng | 1.2.3 | All | All | All |
| Application | Libpng | Libpng | 1.2.30 | All | All | All |
| Application | Libpng | Libpng | 1.2.31 | All | All | All |
| Application | Libpng | Libpng | 1.2.32 | All | All | All |
| Application | Libpng | Libpng | 1.2.33 | All | All | All |
| Application | Libpng | Libpng | 1.2.34 | All | All | All |
| Application | Libpng | Libpng | 1.2.35 | All | All | All |
| Application | Libpng | Libpng | 1.2.36 | All | All | All |
| Application | Libpng | Libpng | 1.2.37 | All | All | All |
| Application | Libpng | Libpng | 1.2.38 | All | All | All |
| Application | Libpng | Libpng | 1.2.39 | All | All | All |
| Application | Libpng | Libpng | 1.2.4 | All | All | All |
| Application | Libpng | Libpng | 1.2.40 | All | All | All |
| Application | Libpng | Libpng | 1.2.41 | All | All | All |
| Application | Libpng | Libpng | 1.2.42 | All | All | All |
| Application | Libpng | Libpng | 1.2.43 | All | All | All |
| Application | Libpng | Libpng | 1.2.44 | All | All | All |
| Application | Libpng | Libpng | 1.2.45 | All | All | All |
| Application | Libpng | Libpng | 1.2.46 | All | All | All |
| Application | Libpng | Libpng | 1.2.47 | All | All | All |
| Application | Libpng | Libpng | 1.2.48 | All | All | All |
| Application | Libpng | Libpng | 1.2.49 | All | All | All |
| Application | Libpng | Libpng | 1.2.50 | All | All | All |
| Application | Libpng | Libpng | 1.2.51 | All | All | All |
| Application | Libpng | Libpng | 1.2.52 | All | All | All |
| Application | Libpng | Libpng | 1.2.53 | All | All | All |
| Application | Libpng | Libpng | 1.2.54 | All | All | All |
| Application | Libpng | Libpng | 1.4.0 | All | All | All |
| Application | Libpng | Libpng | 1.4.1 | All | All | All |
| Application | Libpng | Libpng | 1.4.10 | All | All | All |
| Application | Libpng | Libpng | 1.4.11 | All | All | All |
| Application | Libpng | Libpng | 1.4.12 | All | All | All |
| Application | Libpng | Libpng | 1.4.13 | All | All | All |
| Application | Libpng | Libpng | 1.4.14 | All | All | All |
| Application | Libpng | Libpng | 1.4.15 | All | All | All |
| Application | Libpng | Libpng | 1.4.16 | All | All | All |
| Application | Libpng | Libpng | 1.4.17 | All | All | All |
| Application | Libpng | Libpng | 1.4.2 | All | All | All |
| Application | Libpng | Libpng | 1.4.3 | All | All | All |
| Application | Libpng | Libpng | 1.4.4 | All | All | All |
| Application | Libpng | Libpng | 1.4.5 | All | All | All |
| Application | Libpng | Libpng | 1.4.6 | All | All | All |
| Application | Libpng | Libpng | 1.4.7 | All | All | All |
| Application | Libpng | Libpng | 1.4.8 | All | All | All |
| Application | Libpng | Libpng | 1.4.9 | All | All | All |
| Application | Libpng | Libpng | 1.5.1 | All | All | All |
| Application | Libpng | Libpng | 1.5.10 | All | All | All |
| Application | Libpng | Libpng | 1.5.11 | All | All | All |
| Application | Libpng | Libpng | 1.5.12 | All | All | All |
| Application | Libpng | Libpng | 1.5.13 | All | All | All |
| Application | Libpng | Libpng | 1.5.14 | All | All | All |
| Application | Libpng | Libpng | 1.5.15 | All | All | All |
| Application | Libpng | Libpng | 1.5.16 | All | All | All |
| Application | Libpng | Libpng | 1.5.17 | All | All | All |
| Application | Libpng | Libpng | 1.5.18 | All | All | All |
| Application | Libpng | Libpng | 1.5.19 | All | All | All |
| Application | Libpng | Libpng | 1.5.2 | All | All | All |
| Application | Libpng | Libpng | 1.5.20 | All | All | All |
| Application | Libpng | Libpng | 1.5.21 | All | All | All |
| Application | Libpng | Libpng | 1.5.22 | All | All | All |
| Application | Libpng | Libpng | 1.5.23 | All | All | All |
| Application | Libpng | Libpng | 1.5.24 | All | All | All |
| Application | Libpng | Libpng | 1.5.3 | All | All | All |
| Application | Libpng | Libpng | 1.5.4 | All | All | All |
| Application | Libpng | Libpng | 1.5.5 | All | All | All |
| Application | Libpng | Libpng | 1.5.6 | All | All | All |
| Application | Libpng | Libpng | 1.5.7 | All | All | All |
| Application | Libpng | Libpng | 1.5.8 | All | All | All |
| Application | Libpng | Libpng | 1.5.9 | All | All | All |
| Application | Libpng | Libpng | 1.6.0 | All | All | All |
| Application | Libpng | Libpng | 1.6.1 | All | All | All |
| Application | Libpng | Libpng | 1.6.10 | All | All | All |
| Application | Libpng | Libpng | 1.6.11 | All | All | All |
| Application | Libpng | Libpng | 1.6.12 | All | All | All |
| Application | Libpng | Libpng | 1.6.13 | All | All | All |
| Application | Libpng | Libpng | 1.6.14 | All | All | All |
| Application | Libpng | Libpng | 1.6.15 | All | All | All |
| Application | Libpng | Libpng | 1.6.16 | All | All | All |
| Application | Libpng | Libpng | 1.6.17 | All | All | All |
| Application | Libpng | Libpng | 1.6.18 | All | All | All |
| Application | Libpng | Libpng | 1.6.19 | All | All | All |
| Application | Libpng | Libpng | 1.6.2 | All | All | All |
| Application | Libpng | Libpng | 1.6.3 | All | All | All |
| Application | Libpng | Libpng | 1.6.4 | All | All | All |
| Application | Libpng | Libpng | 1.6.5 | All | All | All |
| Application | Libpng | Libpng | 1.6.6 | All | All | All |
| Application | Libpng | Libpng | 1.6.7 | All | All | All |
| Application | Libpng | Libpng | 1.6.8 | All | All | All |
| Application | Libpng | Libpng | 1.6.9 | All | All | All |
| Application | Libpng | Libpng | 1.0.64 | All | All | All |
| Application | Libpng | Libpng | 1.2.0 | All | All | All |
| Application | Libpng | Libpng | 1.2.1 | All | All | All |
| Application | Libpng | Libpng | 1.2.10 | All | All | All |
| Application | Libpng | Libpng | 1.2.11 | All | All | All |
| Application | Libpng | Libpng | 1.2.12 | All | All | All |
| Application | Libpng | Libpng | 1.2.13 | All | All | All |
| Application | Libpng | Libpng | 1.2.14 | All | All | All |
| Application | Libpng | Libpng | 1.2.15 | All | All | All |
| Application | Libpng | Libpng | 1.2.16 | All | All | All |
| Application | Libpng | Libpng | 1.2.17 | All | All | All |
| Application | Libpng | Libpng | 1.2.18 | All | All | All |
| Application | Libpng | Libpng | 1.2.19 | All | All | All |
| Application | Libpng | Libpng | 1.2.2 | All | All | All |
| Application | Libpng | Libpng | 1.2.20 | All | All | All |
| Application | Libpng | Libpng | 1.2.21 | All | All | All |
| Application | Libpng | Libpng | 1.2.22 | All | All | All |
| Application | Libpng | Libpng | 1.2.23 | All | All | All |
| Application | Libpng | Libpng | 1.2.24 | All | All | All |
| Application | Libpng | Libpng | 1.2.25 | All | All | All |
| Application | Libpng | Libpng | 1.2.26 | All | All | All |
| Application | Libpng | Libpng | 1.2.27 | All | All | All |
| Application | Libpng | Libpng | 1.2.28 | All | All | All |
| Application | Libpng | Libpng | 1.2.29 | All | All | All |
| Application | Libpng | Libpng | 1.2.3 | All | All | All |
| Application | Libpng | Libpng | 1.2.30 | All | All | All |
| Application | Libpng | Libpng | 1.2.31 | All | All | All |
| Application | Libpng | Libpng | 1.2.32 | All | All | All |
| Application | Libpng | Libpng | 1.2.33 | All | All | All |
| Application | Libpng | Libpng | 1.2.34 | All | All | All |
| Application | Libpng | Libpng | 1.2.35 | All | All | All |
| Application | Libpng | Libpng | 1.2.36 | All | All | All |
| Application | Libpng | Libpng | 1.2.37 | All | All | All |
| Application | Libpng | Libpng | 1.2.38 | All | All | All |
| Application | Libpng | Libpng | 1.2.39 | All | All | All |
| Application | Libpng | Libpng | 1.2.4 | All | All | All |
| Application | Libpng | Libpng | 1.2.40 | All | All | All |
| Application | Libpng | Libpng | 1.2.41 | All | All | All |
| Application | Libpng | Libpng | 1.2.42 | All | All | All |
| Application | Libpng | Libpng | 1.2.43 | All | All | All |
| Application | Libpng | Libpng | 1.2.44 | All | All | All |
| Application | Libpng | Libpng | 1.2.45 | All | All | All |
| Application | Libpng | Libpng | 1.2.46 | All | All | All |
| Application | Libpng | Libpng | 1.2.47 | All | All | All |
| Application | Libpng | Libpng | 1.2.48 | All | All | All |
| Application | Libpng | Libpng | 1.2.49 | All | All | All |
| Application | Libpng | Libpng | 1.2.50 | All | All | All |
| Application | Libpng | Libpng | 1.2.51 | All | All | All |
| Application | Libpng | Libpng | 1.2.52 | All | All | All |
| Application | Libpng | Libpng | 1.2.53 | All | All | All |
| Application | Libpng | Libpng | 1.2.54 | All | All | All |
| Application | Libpng | Libpng | 1.4.0 | All | All | All |
| Application | Libpng | Libpng | 1.4.1 | All | All | All |
| Application | Libpng | Libpng | 1.4.10 | All | All | All |
| Application | Libpng | Libpng | 1.4.11 | All | All | All |
| Application | Libpng | Libpng | 1.4.12 | All | All | All |
| Application | Libpng | Libpng | 1.4.13 | All | All | All |
| Application | Libpng | Libpng | 1.4.14 | All | All | All |
| Application | Libpng | Libpng | 1.4.15 | All | All | All |
| Application | Libpng | Libpng | 1.4.16 | All | All | All |
| Application | Libpng | Libpng | 1.4.17 | All | All | All |
| Application | Libpng | Libpng | 1.4.2 | All | All | All |
| Application | Libpng | Libpng | 1.4.3 | All | All | All |
| Application | Libpng | Libpng | 1.4.4 | All | All | All |
| Application | Libpng | Libpng | 1.4.5 | All | All | All |
| Application | Libpng | Libpng | 1.4.6 | All | All | All |
| Application | Libpng | Libpng | 1.4.7 | All | All | All |
| Application | Libpng | Libpng | 1.4.8 | All | All | All |
| Application | Libpng | Libpng | 1.4.9 | All | All | All |
| Application | Libpng | Libpng | 1.5.1 | All | All | All |
| Application | Libpng | Libpng | 1.5.10 | All | All | All |
| Application | Libpng | Libpng | 1.5.11 | All | All | All |
| Application | Libpng | Libpng | 1.5.12 | All | All | All |
| Application | Libpng | Libpng | 1.5.13 | All | All | All |
| Application | Libpng | Libpng | 1.5.14 | All | All | All |
| Application | Libpng | Libpng | 1.5.15 | All | All | All |
| Application | Libpng | Libpng | 1.5.16 | All | All | All |
| Application | Libpng | Libpng | 1.5.17 | All | All | All |
| Application | Libpng | Libpng | 1.5.18 | All | All | All |
| Application | Libpng | Libpng | 1.5.19 | All | All | All |
| Application | Libpng | Libpng | 1.5.2 | All | All | All |
| Application | Libpng | Libpng | 1.5.20 | All | All | All |
| Application | Libpng | Libpng | 1.5.21 | All | All | All |
| Application | Libpng | Libpng | 1.5.22 | All | All | All |
| Application | Libpng | Libpng | 1.5.23 | All | All | All |
| Application | Libpng | Libpng | 1.5.24 | All | All | All |
| Application | Libpng | Libpng | 1.5.3 | All | All | All |
| Application | Libpng | Libpng | 1.5.4 | All | All | All |
| Application | Libpng | Libpng | 1.5.5 | All | All | All |
| Application | Libpng | Libpng | 1.5.6 | All | All | All |
| Application | Libpng | Libpng | 1.5.7 | All | All | All |
| Application | Libpng | Libpng | 1.5.8 | All | All | All |
| Application | Libpng | Libpng | 1.5.9 | All | All | All |
| Application | Libpng | Libpng | 1.6.0 | All | All | All |
| Application | Libpng | Libpng | 1.6.1 | All | All | All |
| Application | Libpng | Libpng | 1.6.10 | All | All | All |
| Application | Libpng | Libpng | 1.6.11 | All | All | All |
| Application | Libpng | Libpng | 1.6.12 | All | All | All |
| Application | Libpng | Libpng | 1.6.13 | All | All | All |
| Application | Libpng | Libpng | 1.6.14 | All | All | All |
| Application | Libpng | Libpng | 1.6.15 | All | All | All |
| Application | Libpng | Libpng | 1.6.16 | All | All | All |
| Application | Libpng | Libpng | 1.6.17 | All | All | All |
| Application | Libpng | Libpng | 1.6.18 | All | All | All |
| Application | Libpng | Libpng | 1.6.19 | All | All | All |
| Application | Libpng | Libpng | 1.6.2 | All | All | All |
| Application | Libpng | Libpng | 1.6.3 | All | All | All |
| Application | Libpng | Libpng | 1.6.4 | All | All | All |
| Application | Libpng | Libpng | 1.6.5 | All | All | All |
| Application | Libpng | Libpng | 1.6.6 | All | All | All |
| Application | Libpng | Libpng | 1.6.7 | All | All | All |
| Application | Libpng | Libpng | 1.6.8 | All | All | All |
| Application | Libpng | Libpng | 1.6.9 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-3443-1 libpng | DEBIAN | www.debian.org | |
| [security-announce] openSUSE-SU-2016:0263-1: critical: Security update f | SUSE | lists.opensuse.org | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| APPLE-SA-2016-03-21-5 OS X El Capitan 10.11.4 and Security Update 2016-002 | APPLE | lists.apple.com | |
| PNG reference library: libpng - Browse /libpng15/1.5.25 at SourceForge.net | CONFIRM | sourceforge.net | |
| oss-security - Status of CVE-2015-8126: libpng buffer overflow in png_set_PLTE | MLIST | www.openwall.com | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| [security-announce] SUSE-SU-2016:0265-1: critical: Security update for j | SUSE | lists.opensuse.org | |
| [SECURITY] Fedora 23 Update: libpng-1.6.17-3.fc23 | FEDORA | lists.fedoraproject.org | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| [security-announce] openSUSE-SU-2016:0270-1: critical: Security update f | SUSE | lists.opensuse.org | |
| PNG reference library: libpng - Browse /libpng16/1.6.20 at SourceForge.net | CONFIRM | sourceforge.net | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| libpng CVE-2015-8472 Incomplete Fix Heap Based Buffer Overflow Vulnerability | BID | www.securityfocus.com | |
| PNG reference library: libpng - Browse /libpng12/1.2.55 at SourceForge.net | CONFIRM | sourceforge.net | |
| [security-announce] SUSE-SU-2016:0256-1: critical: Security update for j | SUSE | lists.opensuse.org | |
| [SECURITY] Fedora 23 Update: libpng15-1.5.25-1.fc23 | FEDORA | lists.fedoraproject.org | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| [SECURITY] Fedora 22 Update: libpng15-1.5.25-1.fc22 | FEDORA | lists.fedoraproject.org | |
| [security-announce] openSUSE-SU-2016:0272-1: important: Security update | SUSE | lists.opensuse.org | |
| Oracle Linux Bulletin - October 2015 | CONFIRM | www.oracle.com | |
| McAfee KnowledgeBase - Intel Security - Security Bulletin: ePolicy Orchestrator update fixes multiple Oracle Java vulnerabilities | CONFIRM | kc.mcafee.com | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| [security-announce] openSUSE-SU-2016:0268-1: critical: Security update f | SUSE | lists.opensuse.org | |
| PNG reference library: libpng - Browse /libpng14/1.4.18 at SourceForge.net | CONFIRM | sourceforge.net | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002 - Apple Support | CONFIRM | support.apple.com | Vendor Advisory |
| [security-announce] openSUSE-SU-2016:0279-1: critical: Security update f | SUSE | lists.opensuse.org | |
| [security-announce] SUSE-SU-2016:0269-1: critical: Security update for j | SUSE | lists.opensuse.org | |
| PNG reference library: libpng - Browse /libpng10/1.0.65 at SourceForge.net | CONFIRM | sourceforge.net | |
| Oracle Critical Patch Update - January 2016 | CONFIRM | www.oracle.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.