Oval Definition:oval:com.ubuntu.trusty:def:20157981000
Revision Date:2015-11-24Version:1
Title:CVE-2015-7981 on Ubuntu 14.04 LTS (trusty) - low.
Description:The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which triggers an out-of-bounds read.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2015-7981
Platform(s):Ubuntu 14.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 14.04 LTS (trusty) is installed.
  • AND Package Information
  • NOT While related to the CVE in some way, the 'chromium-browser' package in trusty is not affected (note: 'uses system libpng').
  • OR NOT While related to the CVE in some way, the 'firefox' package in trusty is not affected (note: 'bundles libpng 1.6.18').
  • OR The 'libpng' package in trusty was vulnerable but has been fixed (note: '1.2.50-1ubuntu2.14.04.1').
  • OR NOT While related to the CVE in some way, the 'thunderbird' package in trusty is not affected (note: 'bundles libpng 1.6.16').
  • BACK