CVE-2016-3981: Buffer Overflow
Published Apr 13, 2016
·Updated
Heap-based buffer overflow in the bmpreadrows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file.
Affected Software
6 affected components
Optipng Project Optipng<=0.7.5
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Apr 13, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3981?
CVE-2016-3981 has a high severity rating due to the risk of denial of service and potential for arbitrary code execution.
2
How do I fix CVE-2016-3981?
To fix CVE-2016-3981, you should upgrade to OptiPNG version 0.7.6 or later.
3
What software is affected by CVE-2016-3981?
CVE-2016-3981 affects OptiPNG versions earlier than 0.7.6 and various Ubuntu and Debian Linux distributions.
4
What might happen if I am affected by CVE-2016-3981?
Being affected by CVE-2016-3981 could lead to application crashes or possible arbitrary code execution.
5
Can CVE-2016-3981 be exploited remotely?
Yes, CVE-2016-3981 can be exploited remotely through crafted image files.