7.5
CVSSv2

CVE-2015-0973

Published: 18/01/2015 Updated: 20/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng prior to 1.5.21 and 1.6.x prior to 1.6.16 allows context-dependent malicious users to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle solaris 11.2

libpng libpng 1.6.0

libpng libpng 1.6.1

libpng libpng 1.6.2

libpng libpng 1.6.10

libpng libpng 1.6.11

libpng libpng 1.6.4

libpng libpng 1.6.5

libpng libpng 1.6.6

libpng libpng 1.6.7

libpng libpng 1.6.14

libpng libpng 1.6.15

libpng libpng 1.6.3

libpng libpng 1.6.8

libpng libpng 1.6.9

libpng libpng 1.6.13

libpng libpng

libpng libpng 1.6.12

apple mac os x

Vendor Advisories

Buffer overflow in the png_read_IDAT_data function in pngrutilc in libpng before 1521 and 16x before 1616 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495 ...