Loading
Generated remediation guidance and an executive summary. No account required.
Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file.
Use CWE-189, Pngcrush Project vendor hub and Pngcrush product page to widen CVE-2015-2158 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2015-7700 for nearby disclosures in the same product family.