{ "schema_version": "1.4.0", "id": "GHSA-fr3h-2jww-582m", "modified": "2025-04-12T12:54:15Z", "published": "2022-05-17T02:38:02Z", "aliases": [ "CVE-2015-7981" ], "details": "The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which triggers an out-of-bounds read.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-7981" }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2016:1430" }, { "type": "WEB", "url": "https://security.gentoo.org/glsa/201611-08" }, { "type": "WEB", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172620.html" }, { "type": "WEB", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172647.html" }, { "type": "WEB", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172663.html" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00033.html" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-updates/2015-11/msg00160.html" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2015-2594.html" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2015-2595.html" }, { "type": "WEB", "url": "http://sourceforge.net/p/libpng/bugs/241" }, { "type": "WEB", "url": "http://sourceforge.net/projects/libpng/files/libpng10/1.0.64" }, { "type": "WEB", "url": "http://sourceforge.net/projects/libpng/files/libpng12/1.2.54" }, { "type": "WEB", "url": "http://sourceforge.net/projects/libpng/files/libpng14/1.4.17" }, { "type": "WEB", "url": "http://www.debian.org/security/2015/dsa-3399" }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2015/10/26/1" }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2015/10/26/3" }, { "type": "WEB", "url": "http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html" }, { "type": "WEB", "url": "http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/77304" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1034393" }, { "type": "WEB", "url": "http://www.ubuntu.com/usn/USN-2815-1" } ], "database_specific": { "cwe_ids": [ "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2015-11-24T20:59:00Z" } }