CVE-2015-8126 describes multiple buffer overflow vulnerabilities in the libpng library, specifically affecting versions before 1.0.64, 1.2.54, 1.4.17, 1.5.24, and 1.6.19. These flaws impact numerous products from vendors like Apple, Canonical, Debian, Oracle, and Red Hat. The vulnerability allows remote attackers to trigger a denial of service or potentially other unspecified impacts by crafting a malicious PNG image with a small bit-depth value in the IHDR chunk. With a CVSS score of 7.5, this vulnerability is considered high severity, indicating a network-based attack with low complexity that could lead to partial compromise of confidentiality, integrity, and availability. The EPSS score is low, suggesting a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered significant community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.64CPE matchmatch criteria | cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* | ||
>= 1.1.1, < 1.2.54CPE matchmatch criteria | cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* | ||
>= 1.3.0, < 1.4.17CPE matchmatch criteria | cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* | ||
>= 1.5.0, < 1.5.24CPE matchmatch criteria | cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* | ||
>= 1.6.0, < 1.6.19CPE matchmatch criteria | cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.