CVE-2015-0973
Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.
- Oracle Solaris
- = 11.2
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 4.3% (90th percentile)
- Weakness
- CWE-120, CWE-119
- NVD status
- Modified
- Published
- 2015-01-18
CVE-2015-0973 at NVD
1 known exploit for CVE-2015-0973
Proof-of-concept code and exploit modules indexed by Sploitus