CVE-2015-7981: Canonical Ubuntu Linux
Medium severity, CVSS 5.0. EPSS: 6.4% chance of exploitation in the next 30 days.
The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which triggers an out-of-bounds read.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only; version 15.10 only
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Libpng Libpng: version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.5 only; version 1.0.6 only; …
- Red Hat Enterprise Linux Desktop: version 7.0 only; version 6.0 only
- Red Hat Enterprise Linux Hpc Node: version 7.0 only; version 6.0 only
- Red Hat Enterprise Linux Hpc Node Eus: version 7.2 only
- Red Hat Enterprise Linux Server: version 7.0 only; version 6.0 only
- Red Hat Enterprise Linux Server Aus: version 7.2 only
- Red Hat Enterprise Linux Server Eus: version 7.2 only; version 6.7.z only
- Red Hat Enterprise Linux Workstation: version 7.0 only; version 6.0 only
Published 2015-11-24. Last modified 2026-06-17.