CVE-2014-9495: Buffer Overflow
Heap-based buffer overflow in the pngcombinerow function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running on 64-bit systems, might allow context-dependent attackers to execute arbitrary code via a "very wide interlaced" PNG image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9495?
CVE-2014-9495 has a high severity rating due to the potential for remote code execution through a heap-based buffer overflow.
How do I fix CVE-2014-9495?
To fix CVE-2014-9495, upgrade to libpng version 1.5.21 or 1.6.16 and later.
Which systems are affected by CVE-2014-9495?
CVE-2014-9495 affects libpng versions before 1.5.21 and 1.6.x before 1.6.16 on 64-bit systems.
Can CVE-2014-9495 lead to data loss?
While the primary threat of CVE-2014-9495 is arbitrary code execution, it could potentially lead to data loss depending on the malicious code executed.
Who is vulnerable to CVE-2014-9495?
Users of macOS Yosemite up to version 10.11.3 and those using unsupported versions of libpng are vulnerable to CVE-2014-9495.