LWN.net Logo

libpng: multiple vulnerabilities

Package(s):libpng CVE #(s):CVE-2011-2690 CVE-2011-2691 CVE-2011-2692
Created:July 19, 2011 Updated:October 17, 2011
Description: From the CVE entries:

Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the png_rgb_to_gray function but not the png_set_expand function, allows remote attackers to overwrite memory with an arbitrary amount of data, and possibly have unspecified other impact, via a crafted PNG image. (CVE-2011-2690)

The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function call using a NULL pointer argument instead of an empty-string argument, which allows remote attackers to cause a denial of service (application crash) via a crafted PNG image. (CVE-2011-2691)

The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted PNG image that triggers the reading of uninitialized memory. (CVE-2011-2692)

Alerts:
Mandriva MDVSA-2011:151 2011-10-17
CentOS CESA-2011:1104 2011-09-22
Fedora FEDORA-2011-10954 2011-08-17
Fedora FEDORA-2011-10928 2011-08-17
openSUSE openSUSE-SU-2011:0915-1 2011-08-17
CentOS CESA-2011:1103 2011-08-14
Pardus 2011-105 2011-08-08
Scientific Linux SL-libp-20110728 2011-07-28
Fedora FEDORA-2011-9336 2011-07-15
Scientific Linux SL-libp-20110728 2011-07-28
Scientific Linux SL-libp-20110728 2011-07-28
Red Hat RHSA-2011:1105-01 2011-07-28
Red Hat RHSA-2011:1104-01 2011-07-28
Red Hat RHSA-2011:1103-01 2011-07-28
Debian DSA-2287-1 2011-07-28
Ubuntu USN-1175-1 2011-07-26
Fedora FEDORA-2011-8867 2011-06-29
Fedora FEDORA-2011-8844 2011-06-29
Fedora FEDORA-2011-9343 2011-07-15
Oracle ELSA-2012-0317 2012-02-21
Gentoo 201206-15 2012-06-22

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds