oss-sec mailing list archives

Re: CVE Request: libpng 1.6.15 Heap Overflow


From: cve-assign () mitre org
Date: Sat, 3 Jan 2015 19:05:23 -0500 (EST)


I am requesting a CVE for a heap-overflow in libpng 1.6.15. It's my
understanding that versions 1.6.9-1.6.15 are vulnerable, and according to
patch notes it looks like some revisions in the 1.5 branch may have been
affected as well. However, I've only tested 1.6.15 and can only speak for
it.

Link to announcement of new version:
http://sourceforge.net/p/png-mng/mailman/message/33173461/

Link to a description of the vulnerability:
http://tfpwn.com/files/libpng_heap_overflow_1.6.15.txt

Please let me know!

Use CVE-2014-9495.

---

CVE assignment team, MITRE CVE Numbering Authority M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]


Current thread: