Libpng 'pngwutil. c' Remote Code Execution Vulnerability (CVE-2015-8540)
Libpng 'pngwutil. c' Remote Code Execution Vulnerability (CVE-2015-8540)
Release date:
Updated on:
Affected Systems:
Libpng 1.5.x <1.5.26
Libpng 1.4.x <1.4.19
Libpng 1.3.x
Libpng 1.2.x <1.2.56
Libpng 1.1.x
Libpng 1.0.x <1.0.66
Libpng 0.90 <= 0.99
Description:
CVE (CAN) ID: CVE-2015-8540
Libpng is a PNG graphic parsing function library for various applications.
In some libpng versions, the pngwutil. c/png_check_keyword function has the integer overflow vulnerability. Remote attackers can execute arbitrary code by triggering out-of-range reads.
<* Source: xiaoqixue_1
*>
Suggestion:
Vendor patch:
Libpng
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://sourceforge.net/projects/libpng/files/libpng10/1.0.66/
Http://sourceforge.net/p/libpng/bugs/244/
Http://sourceforge.net/projects/libpng/files/libpng12/1.2.56/
Http://sourceforge.net/projects/libpng/files/libpng14/1.4.19/
This article permanently updates the link address: