CVE-2015-7981
The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which triggers an out-of-bounds read.
- Canonical Ubuntu Linux
- = 12.04, 14.04, 15.04, 15.10
- Debian Debian Linux
- = 7.0, 8.0
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 6.4% (93th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2015-11-24
CVE-2015-7981 at NVD
No indexed exploits for CVE-2015-7981 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2015-7981 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.