CVE-2015-0973: Buffer Overflow
Buffer overflow in the pngreadIDATdata function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0973?
CVE-2015-0973 has a high severity rating due to the potential for arbitrary code execution.
How do I fix CVE-2015-0973?
To remediate CVE-2015-0973, update to libpng version 1.5.21 or 1.6.16 or later.
What software is affected by CVE-2015-0973?
CVE-2015-0973 affects libpng versions prior to 1.5.21 and 1.6.x versions before 1.6.16, along with certain versions of Oracle Solaris and macOS.
Can CVE-2015-0973 be exploited remotely?
Yes, CVE-2015-0973 can be exploited by context-dependent attackers via specially crafted IDAT data.
Is there a way to detect if my system is vulnerable to CVE-2015-0973?
You can check the version of libpng installed on your system against the vulnerable versions to determine if you are at risk from CVE-2015-0973.