CVE-2015-8540: High severity redhat Enterprise Linux Desktop Supplementary vulnerability
An underflow read was found in pngcheckkeyword in pngwutil.c in libpng-1.2.54:
If the data of "key" is only ' ' (0x20), it will read a byte before the buffer in line 1288.
This issue impacts upstream versions 1.2.55, 1.0.65, 1.4.18, and 1.5.25 of libpng.
An attacker could possibly use this flaw to cause an out-of-bounds read by tricking an unsuspecting user into processing a specially crafted PNG image.
CVE assignment:
http://seclists.org/oss-sec/2015/q4/469
Upstream issue:
http://sourceforge.net/p/libpng/bugs/244/
Upstream patch:
http://sourceforge.net/p/libpng/code/ci/d9006f683c641793252d92254a75ae9b815b42ed/
Other sources
Integer underflow in the pngcheckkeyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8540?
CVE-2015-8540 is classified as a moderate severity vulnerability due to integer underflow in libpng.
How do I fix CVE-2015-8540?
To fix CVE-2015-8540, upgrade libpng to version 1.0.66, 1.2.56, 1.4.19, or 1.5.26 or later.
Which versions of libpng are affected by CVE-2015-8540?
CVE-2015-8540 affects libpng versions from 0.90 through 1.5.25.
Can CVE-2015-8540 be exploited remotely?
Yes, CVE-2015-8540 can be exploited remotely if the vulnerable library is used in an application that processes untrusted PNG images.
What software utilizes libpng and is affected by CVE-2015-8540?
Software that utilizes affected versions of libpng, such as certain versions of F5 Traffix SDC, may be affected by CVE-2015-8540.