CVE-2015-8126: Multiple buffer overflows in libpng

Post any defects you find in the released or beta versions of the ImageMagick software here. Include the ImageMagick version, OS, and any command-line required to reproduce the problem. Got a patch for a bug? Post it here.
Post Reply
spender
Posts: 4
Joined: 2015-11-16T05:37:14-07:00
Authentication code: 1151

CVE-2015-8126: Multiple buffer overflows in libpng

Post by spender »

Is CVE-2015-8126 a problem for ImageMagick? There are probably quite a number of users with ImageMagick running on servers, so if there is a problem, it probably needs looking at fairly quickly.

/spender
User avatar
glennrp
Posts: 1147
Joined: 2006-04-01T08:16:32-07:00
Location: Maryland 39.26.30N 76.16.01W

Re: CVE-2015-8126: Multiple buffer overflows in libpng

Post by glennrp »

ImageMagick is not vulnerable to CVE-2015-8126. In fact I do not know of any libpng application that is actually vulnerable, although it would be possible to write one.
Post Reply