Vulnerabilities > CVE-2015-7700 - Double Free vulnerability in Pngcrush Project Pngcrush

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
pngcrush-project
CWE-415
critical
nessus

Summary

Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors.

Vulnerable Configurations

Part Description Count
Application
Pngcrush_Project
141

Common Weakness Enumeration (CWE)

Nessus

  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2018-43.NASL
    descriptionThis update for pngcrush fixes the following issues : - CVE-2015-7700: Fix for a double-free vulnerability in the sPLT chunk structure and png.c (boo#1056770)
    last seen2020-06-05
    modified2018-01-16
    plugin id106070
    published2018-01-16
    reporterThis script is Copyright (C) 2018-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/106070
    titleopenSUSE Security Update : pngcrush (openSUSE-2018-43)
  • NASL familyAmazon Linux Local Security Checks
    NASL idALA_ALAS-2016-646.NASL
    descriptionA double-free bug was discovered in pngcrush
    last seen2020-06-01
    modified2020-06-02
    plugin id88658
    published2016-02-10
    reporterThis script is Copyright (C) 2016-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/88658
    titleAmazon Linux AMI : pngcrush (ALAS-2016-646)