PT-2011-1112 · Libpng+1 · Libpng+1

Huzaifa S. Sidhpurwala

·

Published

2011-07-17

·

Updated

2024-09-06

·

CVE-2011-2690

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libpng versions 1.0.x through 1.0.54 libpng versions 1.2.x through 1.2.44 libpng versions 1.4.x through 1.4.7 libpng versions 1.5.x through 1.5.3 libpng versions prior to 1.5.10
Description The issue is related to multiple vulnerabilities in the libpng package, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A buffer overflow vulnerability is present in libpng when used by an application that calls the png rgb to gray function but not the png set expand function, allowing remote attackers to overwrite memory with an arbitrary amount of data via a crafted PNG image.
Recommendations For libpng versions 1.0.x through 1.0.54, update to version 1.0.55 or later. For libpng versions 1.2.x through 1.2.44, update to version 1.2.45 or later. For libpng versions 1.4.x through 1.4.7, update to version 1.4.8 or later. For libpng versions 1.5.x through 1.5.3, update to version 1.5.4 or later. For libpng versions prior to 1.5.10, update to version 1.5.10 or later. As a temporary workaround, consider restricting the use of libpng until a patch is available. Avoid using the png rgb to gray function without the png set expand function in affected applications.

Fix

Out of bounds Read

Memory Leak

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06313
BDU:2015-06314
BDU:2015-06316
BDU:2015-06317
BDU:2015-09650
CVE-2011-2690
DSA-2287-1
OESA-2024-2091
OPENSUSE-SU-2024:10050-1
RHSA-2011:1104
RHSA-2011:1105
RHSA-2011_1104
RHSA-2011_1105

Affected Products

Red Hat
Libpng