Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8126.
2016-01-21T15:59:00.117
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 7.3 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | apple | mac_os_x | ≤ 10.11.3 | Yes |
Application | libpng | libpng | 1.0.64 | Yes |
Application | libpng | libpng | 1.2.0 | Yes |
Application | libpng | libpng | 1.2.1 | Yes |
Application | libpng | libpng | 1.2.2 | Yes |
Application | libpng | libpng | 1.2.3 | Yes |
Application | libpng | libpng | 1.2.4 | Yes |
Application | libpng | libpng | 1.2.10 | Yes |
Application | libpng | libpng | 1.2.11 | Yes |
Application | libpng | libpng | 1.2.12 | Yes |
Application | libpng | libpng | 1.2.13 | Yes |
Application | libpng | libpng | 1.2.14 | Yes |
Application | libpng | libpng | 1.2.15 | Yes |
Application | libpng | libpng | 1.2.16 | Yes |
Application | libpng | libpng | 1.2.17 | Yes |
Application | libpng | libpng | 1.2.18 | Yes |
Application | libpng | libpng | 1.2.19 | Yes |
Application | libpng | libpng | 1.2.20 | Yes |
Application | libpng | libpng | 1.2.21 | Yes |
Application | libpng | libpng | 1.2.22 | Yes |
Application | libpng | libpng | 1.2.23 | Yes |
Application | libpng | libpng | 1.2.24 | Yes |
Application | libpng | libpng | 1.2.25 | Yes |
Application | libpng | libpng | 1.2.26 | Yes |
Application | libpng | libpng | 1.2.27 | Yes |
Application | libpng | libpng | 1.2.28 | Yes |
Application | libpng | libpng | 1.2.29 | Yes |
Application | libpng | libpng | 1.2.30 | Yes |
Application | libpng | libpng | 1.2.31 | Yes |
Application | libpng | libpng | 1.2.32 | Yes |
Application | libpng | libpng | 1.2.33 | Yes |
Application | libpng | libpng | 1.2.34 | Yes |
Application | libpng | libpng | 1.2.35 | Yes |
Application | libpng | libpng | 1.2.36 | Yes |
Application | libpng | libpng | 1.2.37 | Yes |
Application | libpng | libpng | 1.2.38 | Yes |
Application | libpng | libpng | 1.2.39 | Yes |
Application | libpng | libpng | 1.2.40 | Yes |
Application | libpng | libpng | 1.2.41 | Yes |
Application | libpng | libpng | 1.2.42 | Yes |
Application | libpng | libpng | 1.2.43 | Yes |
Application | libpng | libpng | 1.2.44 | Yes |
Application | libpng | libpng | 1.2.45 | Yes |
Application | libpng | libpng | 1.2.46 | Yes |
Application | libpng | libpng | 1.2.47 | Yes |
Application | libpng | libpng | 1.2.48 | Yes |
Application | libpng | libpng | 1.2.49 | Yes |
Application | libpng | libpng | 1.2.50 | Yes |
Application | libpng | libpng | 1.2.51 | Yes |
Application | libpng | libpng | 1.2.52 | Yes |
Application | libpng | libpng | 1.2.53 | Yes |
Application | libpng | libpng | 1.2.54 | Yes |
Application | libpng | libpng | 1.4.0 | Yes |
Application | libpng | libpng | 1.4.1 | Yes |
Application | libpng | libpng | 1.4.2 | Yes |
Application | libpng | libpng | 1.4.3 | Yes |
Application | libpng | libpng | 1.4.4 | Yes |
Application | libpng | libpng | 1.4.5 | Yes |
Application | libpng | libpng | 1.4.6 | Yes |
Application | libpng | libpng | 1.4.7 | Yes |
Application | libpng | libpng | 1.4.8 | Yes |
Application | libpng | libpng | 1.4.9 | Yes |
Application | libpng | libpng | 1.4.10 | Yes |
Application | libpng | libpng | 1.4.11 | Yes |
Application | libpng | libpng | 1.4.12 | Yes |
Application | libpng | libpng | 1.4.13 | Yes |
Application | libpng | libpng | 1.4.14 | Yes |
Application | libpng | libpng | 1.4.15 | Yes |
Application | libpng | libpng | 1.4.16 | Yes |
Application | libpng | libpng | 1.4.17 | Yes |
Application | libpng | libpng | 1.5.1 | Yes |
Application | libpng | libpng | 1.5.2 | Yes |
Application | libpng | libpng | 1.5.3 | Yes |
Application | libpng | libpng | 1.5.4 | Yes |
Application | libpng | libpng | 1.5.5 | Yes |
Application | libpng | libpng | 1.5.6 | Yes |
Application | libpng | libpng | 1.5.7 | Yes |
Application | libpng | libpng | 1.5.8 | Yes |
Application | libpng | libpng | 1.5.9 | Yes |
Application | libpng | libpng | 1.5.10 | Yes |
Application | libpng | libpng | 1.5.11 | Yes |
Application | libpng | libpng | 1.5.12 | Yes |
Application | libpng | libpng | 1.5.13 | Yes |
Application | libpng | libpng | 1.5.14 | Yes |
Application | libpng | libpng | 1.5.15 | Yes |
Application | libpng | libpng | 1.5.16 | Yes |
Application | libpng | libpng | 1.5.17 | Yes |
Application | libpng | libpng | 1.5.18 | Yes |
Application | libpng | libpng | 1.5.19 | Yes |
Application | libpng | libpng | 1.5.20 | Yes |
Application | libpng | libpng | 1.5.21 | Yes |
Application | libpng | libpng | 1.5.22 | Yes |
Application | libpng | libpng | 1.5.23 | Yes |
Application | libpng | libpng | 1.5.24 | Yes |
Application | libpng | libpng | 1.6.0 | Yes |
Application | libpng | libpng | 1.6.1 | Yes |
Application | libpng | libpng | 1.6.2 | Yes |
Application | libpng | libpng | 1.6.3 | Yes |
Application | libpng | libpng | 1.6.4 | Yes |
Application | libpng | libpng | 1.6.5 | Yes |
Application | libpng | libpng | 1.6.6 | Yes |
Application | libpng | libpng | 1.6.7 | Yes |
Application | libpng | libpng | 1.6.8 | Yes |
Application | libpng | libpng | 1.6.9 | Yes |
Application | libpng | libpng | 1.6.10 | Yes |
Application | libpng | libpng | 1.6.11 | Yes |
Application | libpng | libpng | 1.6.12 | Yes |
Application | libpng | libpng | 1.6.13 | Yes |
Application | libpng | libpng | 1.6.14 | Yes |
Application | libpng | libpng | 1.6.15 | Yes |
Application | libpng | libpng | 1.6.16 | Yes |
Application | libpng | libpng | 1.6.17 | Yes |
Application | libpng | libpng | 1.6.18 | Yes |
Application | libpng | libpng | 1.6.19 | Yes |