libpng CVE-2015-0973 Multiple Heap Based Buffer Overflow Vulnerabilities
BID:71994
Info
libpng CVE-2015-0973 Multiple Heap Based Buffer Overflow Vulnerabilities
| Bugtraq ID: | 71994 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2015-0973 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 10 2015 12:00AM |
| Updated: | Jul 06 2016 02:08PM |
| Credit: | John Bowler |
| Vulnerable: |
libpng libpng 1.5.5 libpng libpng 1.5.4 libpng libpng 1.5 libpng libpng 1.5.8 libpng libpng 1.5.7 libpng libpng 1.5.6 libpng libpng 1.5.10 IBM Tivoli Common Reporting 2.1 |
| Not Vulnerable: | |
Discussion
libpng CVE-2015-0973 Multiple Heap Based Buffer Overflow Vulnerabilities
libpng is prone to multiple heap-based buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage these issues to execute arbitrary code in the context of the application that uses the affected library. Failed attacks will cause denial-of-service conditions.
libpng is prone to multiple heap-based buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage these issues to execute arbitrary code in the context of the application that uses the affected library. Failed attacks will cause denial-of-service conditions.