HomeLibpngCVE-2015-8126

CVE-2015-8126

UNKNOWN
7.5CVSS
Published: 2015-11-13
Updated: 2025-04-12
AI Analysis

Description

Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.

CVSS Metrics

Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Access Vector
network
Access Cmplx
low
Auth
none
Confidentiality
partial
Integrity
partial
Availability
partial
Weaknesses
CWE-120

Metadata

Primary Vendor
LIBPNG
Published
11/13/2015
Last Modified
4/12/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

libpng : libpnglibpng : libpnglibpng : libpnglibpng : libpnglibpng : libpngfedoraproject : fedorafedoraproject : fedorafedoraproject : fedoraopensuse : leapopensuse : opensuseopensuse : opensusesuse : linux_enterprise_desktopsuse : linux_enterprise_desktopsuse : linux_enterprise_desktopsuse : linux_enterprise_desktopsuse : linux_enterprise_serversuse : linux_enterprise_serverdebian : debian_linuxdebian : debian_linuxdebian : debian_linuxredhat : satelliteredhat : enterprise_linux_desktopredhat : enterprise_linux_desktopredhat : enterprise_linux_eusredhat : enterprise_linux_eusredhat : enterprise_linux_eusredhat : enterprise_linux_eusredhat : enterprise_linux_eusredhat : enterprise_linux_eusredhat : enterprise_linux_eusredhat : enterprise_linux_serverredhat : enterprise_linux_serverredhat : enterprise_linux_server_ausredhat : enterprise_linux_server_ausredhat : enterprise_linux_server_ausredhat : enterprise_linux_server_ausredhat : enterprise_linux_server_ausredhat : enterprise_linux_server_tusredhat : enterprise_linux_server_tusredhat : enterprise_linux_server_tusredhat : enterprise_linux_server_tusredhat : enterprise_linux_workstationredhat : enterprise_linux_workstationredhat : satelliteoracle : jdkoracle : jdkoracle : jdkoracle : jdkoracle : jreoracle : jreoracle : jreoracle : jreoracle : linuxoracle : linuxoracle : solarisapple : mac_os_xcanonical : ubuntu_linuxcanonical : ubuntu_linuxcanonical : ubuntu_linuxcanonical : ubuntu_linux

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2015-8126 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com