CVE-2015-8472
Summary
| CVE | CVE-2015-8472 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-01-21 15:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8126. |
Risk And Classification
Primary CVSS: v3.0 7.3 HIGH from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Problem Types: CWE-119 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.3 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
LowCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | All | All | All | All |
| Application | Libpng | Libpng | 1.0.64 | All | All | All |
| Application | Libpng | Libpng | 1.2.0 | All | All | All |
| Application | Libpng | Libpng | 1.2.1 | All | All | All |
| Application | Libpng | Libpng | 1.2.10 | All | All | All |
| Application | Libpng | Libpng | 1.2.11 | All | All | All |
| Application | Libpng | Libpng | 1.2.12 | All | All | All |
| Application | Libpng | Libpng | 1.2.13 | All | All | All |
| Application | Libpng | Libpng | 1.2.14 | All | All | All |
| Application | Libpng | Libpng | 1.2.15 | All | All | All |
| Application | Libpng | Libpng | 1.2.16 | All | All | All |
| Application | Libpng | Libpng | 1.2.17 | All | All | All |
| Application | Libpng | Libpng | 1.2.18 | All | All | All |
| Application | Libpng | Libpng | 1.2.19 | All | All | All |
| Application | Libpng | Libpng | 1.2.2 | All | All | All |
| Application | Libpng | Libpng | 1.2.20 | All | All | All |
| Application | Libpng | Libpng | 1.2.21 | All | All | All |
| Application | Libpng | Libpng | 1.2.22 | All | All | All |
| Application | Libpng | Libpng | 1.2.23 | All | All | All |
| Application | Libpng | Libpng | 1.2.24 | All | All | All |
| Application | Libpng | Libpng | 1.2.25 | All | All | All |
| Application | Libpng | Libpng | 1.2.26 | All | All | All |
| Application | Libpng | Libpng | 1.2.27 | All | All | All |
| Application | Libpng | Libpng | 1.2.28 | All | All | All |
| Application | Libpng | Libpng | 1.2.29 | All | All | All |
| Application | Libpng | Libpng | 1.2.3 | All | All | All |
| Application | Libpng | Libpng | 1.2.30 | All | All | All |
| Application | Libpng | Libpng | 1.2.31 | All | All | All |
| Application | Libpng | Libpng | 1.2.32 | All | All | All |
| Application | Libpng | Libpng | 1.2.33 | All | All | All |
| Application | Libpng | Libpng | 1.2.34 | All | All | All |
| Application | Libpng | Libpng | 1.2.35 | All | All | All |
| Application | Libpng | Libpng | 1.2.36 | All | All | All |
| Application | Libpng | Libpng | 1.2.37 | All | All | All |
| Application | Libpng | Libpng | 1.2.38 | All | All | All |
| Application | Libpng | Libpng | 1.2.39 | All | All | All |
| Application | Libpng | Libpng | 1.2.4 | All | All | All |
| Application | Libpng | Libpng | 1.2.40 | All | All | All |
| Application | Libpng | Libpng | 1.2.41 | All | All | All |
| Application | Libpng | Libpng | 1.2.42 | All | All | All |
| Application | Libpng | Libpng | 1.2.43 | All | All | All |
| Application | Libpng | Libpng | 1.2.44 | All | All | All |
| Application | Libpng | Libpng | 1.2.45 | All | All | All |
| Application | Libpng | Libpng | 1.2.46 | All | All | All |
| Application | Libpng | Libpng | 1.2.47 | All | All | All |
| Application | Libpng | Libpng | 1.2.48 | All | All | All |
| Application | Libpng | Libpng | 1.2.49 | All | All | All |
| Application | Libpng | Libpng | 1.2.50 | All | All | All |
| Application | Libpng | Libpng | 1.2.51 | All | All | All |
| Application | Libpng | Libpng | 1.2.52 | All | All | All |
| Application | Libpng | Libpng | 1.2.53 | All | All | All |
| Application | Libpng | Libpng | 1.2.54 | All | All | All |
| Application | Libpng | Libpng | 1.4.0 | All | All | All |
| Application | Libpng | Libpng | 1.4.1 | All | All | All |
| Application | Libpng | Libpng | 1.4.10 | All | All | All |
| Application | Libpng | Libpng | 1.4.11 | All | All | All |
| Application | Libpng | Libpng | 1.4.12 | All | All | All |
| Application | Libpng | Libpng | 1.4.13 | All | All | All |
| Application | Libpng | Libpng | 1.4.14 | All | All | All |
| Application | Libpng | Libpng | 1.4.15 | All | All | All |
| Application | Libpng | Libpng | 1.4.16 | All | All | All |
| Application | Libpng | Libpng | 1.4.17 | All | All | All |
| Application | Libpng | Libpng | 1.4.2 | All | All | All |
| Application | Libpng | Libpng | 1.4.3 | All | All | All |
| Application | Libpng | Libpng | 1.4.4 | All | All | All |
| Application | Libpng | Libpng | 1.4.5 | All | All | All |
| Application | Libpng | Libpng | 1.4.6 | All | All | All |
| Application | Libpng | Libpng | 1.4.7 | All | All | All |
| Application | Libpng | Libpng | 1.4.8 | All | All | All |
| Application | Libpng | Libpng | 1.4.9 | All | All | All |
| Application | Libpng | Libpng | 1.5.1 | All | All | All |
| Application | Libpng | Libpng | 1.5.10 | All | All | All |
| Application | Libpng | Libpng | 1.5.11 | All | All | All |
| Application | Libpng | Libpng | 1.5.12 | All | All | All |
| Application | Libpng | Libpng | 1.5.13 | All | All | All |
| Application | Libpng | Libpng | 1.5.14 | All | All | All |
| Application | Libpng | Libpng | 1.5.15 | All | All | All |
| Application | Libpng | Libpng | 1.5.16 | All | All | All |
| Application | Libpng | Libpng | 1.5.17 | All | All | All |
| Application | Libpng | Libpng | 1.5.18 | All | All | All |
| Application | Libpng | Libpng | 1.5.19 | All | All | All |
| Application | Libpng | Libpng | 1.5.2 | All | All | All |
| Application | Libpng | Libpng | 1.5.20 | All | All | All |
| Application | Libpng | Libpng | 1.5.21 | All | All | All |
| Application | Libpng | Libpng | 1.5.22 | All | All | All |
| Application | Libpng | Libpng | 1.5.23 | All | All | All |
| Application | Libpng | Libpng | 1.5.24 | All | All | All |
| Application | Libpng | Libpng | 1.5.3 | All | All | All |
| Application | Libpng | Libpng | 1.5.4 | All | All | All |
| Application | Libpng | Libpng | 1.5.5 | All | All | All |
| Application | Libpng | Libpng | 1.5.6 | All | All | All |
| Application | Libpng | Libpng | 1.5.7 | All | All | All |
| Application | Libpng | Libpng | 1.5.8 | All | All | All |
| Application | Libpng | Libpng | 1.5.9 | All | All | All |
| Application | Libpng | Libpng | 1.6.0 | All | All | All |
| Application | Libpng | Libpng | 1.6.1 | All | All | All |
| Application | Libpng | Libpng | 1.6.10 | All | All | All |
| Application | Libpng | Libpng | 1.6.11 | All | All | All |
| Application | Libpng | Libpng | 1.6.12 | All | All | All |
| Application | Libpng | Libpng | 1.6.13 | All | All | All |
| Application | Libpng | Libpng | 1.6.14 | All | All | All |
| Application | Libpng | Libpng | 1.6.15 | All | All | All |
| Application | Libpng | Libpng | 1.6.16 | All | All | All |
| Application | Libpng | Libpng | 1.6.17 | All | All | All |
| Application | Libpng | Libpng | 1.6.18 | All | All | All |
| Application | Libpng | Libpng | 1.6.19 | All | All | All |
| Application | Libpng | Libpng | 1.6.2 | All | All | All |
| Application | Libpng | Libpng | 1.6.3 | All | All | All |
| Application | Libpng | Libpng | 1.6.4 | All | All | All |
| Application | Libpng | Libpng | 1.6.5 | All | All | All |
| Application | Libpng | Libpng | 1.6.6 | All | All | All |
| Application | Libpng | Libpng | 1.6.7 | All | All | All |
| Application | Libpng | Libpng | 1.6.8 | All | All | All |
| Application | Libpng | Libpng | 1.6.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| [security-announce] openSUSE-SU-2016:0263-1: critical: Security update f | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| [SECURITY] Fedora 23 Update: libpng15-1.5.25-1.fc23 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [security-announce] openSUSE-SU-2016:0268-1: critical: Security update f | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| oss-security - Status of CVE-2015-8126: libpng buffer overflow in png_set_PLTE | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| [security-announce] openSUSE-SU-2016:0279-1: critical: Security update f | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2016:0270-1: critical: Security update f | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| [security-announce] SUSE-SU-2016:0256-1: critical: Security update for j | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Debian -- Security Information -- DSA-3443-1 libpng | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [security-announce] openSUSE-SU-2016:0272-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Vendor Advisory |
| [SECURITY] Fedora 23 Update: libpng-1.6.17-3.fc23 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| McAfee KnowledgeBase - Intel Security - Security Bulletin: ePolicy Orchestrator update fixes multiple Oracle Java vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | kc.mcafee.com | |
| [SECURITY] Fedora 22 Update: libpng15-1.5.25-1.fc22 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| PNG reference library: libpng - Browse /libpng14/1.4.18 at SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| Oracle Critical Patch Update - January 2016 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Vendor Advisory |
| libpng CVE-2015-8472 Incomplete Fix Heap Based Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [security-announce] SUSE-SU-2016:0269-1: critical: Security update for j | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| PNG reference library: libpng - Browse /libpng15/1.5.25 at SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| PNG reference library: libpng - Browse /libpng12/1.2.55 at SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| APPLE-SA-2016-03-21-5 OS X El Capitan 10.11.4 and Security Update 2016-002 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| [security-announce] SUSE-SU-2016:0265-1: critical: Security update for j | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Oracle Linux Bulletin - October 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| PNG reference library: libpng - Browse /libpng10/1.0.65 at SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| PNG reference library: libpng - Browse /libpng16/1.6.20 at SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.