Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.
2015-01-18T18:59:03.020
2025-06-09T16:15:24.780
Deferred
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | oracle | solaris | 11.2 | Yes |
Application | libpng | libpng | ≤ 1.5.20 | Yes |
Application | libpng | libpng | 1.6.0 | Yes |
Application | libpng | libpng | 1.6.0 | Yes |
Application | libpng | libpng | 1.6.1 | Yes |
Application | libpng | libpng | 1.6.1 | Yes |
Application | libpng | libpng | 1.6.2 | Yes |
Application | libpng | libpng | 1.6.2 | Yes |
Application | libpng | libpng | 1.6.3 | Yes |
Application | libpng | libpng | 1.6.3 | Yes |
Application | libpng | libpng | 1.6.4 | Yes |
Application | libpng | libpng | 1.6.4 | Yes |
Application | libpng | libpng | 1.6.5 | Yes |
Application | libpng | libpng | 1.6.6 | Yes |
Application | libpng | libpng | 1.6.7 | Yes |
Application | libpng | libpng | 1.6.7 | Yes |
Application | libpng | libpng | 1.6.8 | Yes |
Application | libpng | libpng | 1.6.8 | Yes |
Application | libpng | libpng | 1.6.9 | Yes |
Application | libpng | libpng | 1.6.9 | Yes |
Application | libpng | libpng | 1.6.10 | Yes |
Application | libpng | libpng | 1.6.10 | Yes |
Application | libpng | libpng | 1.6.11 | Yes |
Application | libpng | libpng | 1.6.11 | Yes |
Application | libpng | libpng | 1.6.12 | Yes |
Application | libpng | libpng | 1.6.13 | Yes |
Application | libpng | libpng | 1.6.13 | Yes |
Application | libpng | libpng | 1.6.14 | Yes |
Application | libpng | libpng | 1.6.14 | Yes |
Application | libpng | libpng | 1.6.15 | Yes |
Application | libpng | libpng | 1.6.15 | Yes |
Operating System | apple | mac_os_x | ≤ 10.11.3 | Yes |