CVE-2011-2501
published 2011-07-17CVE-2011-2501: The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote…
PriorityP424medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
3.48%
87.9th percentile
The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a CVE-2004-0421 regression. NOTE: this is called an off-by-one error by some sources.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| libpng | libpng | >= 1.0.0 < 1.0.55 | 1.0.55 |
| libpng | libpng | >= 1.2.0 < 1.2.45 | 1.2.45 |
| libpng | libpng | >= 1.4.0 < 1.4.8 | 1.4.8 |
| libpng | libpng | >= 1.5.0 < 1.5.4 | 1.5.4 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_ubuntu6.5MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8m2c-g35f-jj8v: The png_format_buffer function in pngerror
ghsa_unreviewed·2022-05-13·CVSS 5.0
CVE-2011-2501 [MEDIUM] CWE-125 GHSA-8m2c-g35f-jj8v: The png_format_buffer function in pngerror
The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a CVE-2004-0421 regression. NOTE: this is called an off-by-one error by some sources.
Ubuntu
libpng vulnerabilities
vendor_ubuntu·2011-07-26·CVSS 6.5
CVE-2011-2692 [MEDIUM] libpng vulnerabilities
Title: libpng vulnerabilities
Summary: Libpng could be made to run programs as your login if it opened a
specially crafted file.
Frank Busse discovered that libpng did not properly handle certain
malformed PNG images. If a user or automated system were tricked into
opening a crafted PNG file, an attacker could cause libpng to crash,
resulting in a denial of service. This issue only affected Ubuntu
10.04 LTS, 10.10, and 11.04. (CVE-2011-2501)
It was discovered that libpng did not properly handle certain malformed PNG
images. If a user or automated system were tricked into opening a crafted
PNG file, an attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2011-2690)
Frank Busse discovered that libpng did no
Red Hat
libpng: regression of CVE-2004-0421 in 1.2.23+
vendor_redhat·2011-06-07·CVSS 5.0
CVE-2011-2501 [MEDIUM] libpng: regression of CVE-2004-0421 in 1.2.23+
libpng: regression of CVE-2004-0421 in 1.2.23+
The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a CVE-2004-0421 regression. NOTE: this is called an off-by-one error by some sources.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
bugzilla·2011-06-29·CVSS 5.0
CVE-2011-2501 [MEDIUM] CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=717084
Please note: this issue affects multiple
Bugzilla
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
bugzilla·2011-06-29·CVSS 5.0
CVE-2011-2501 [MEDIUM] CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=717084
Please note: this issue affects multiple
Bugzilla
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
bugzilla·2011-06-29·CVSS 5.0
CVE-2011-2501 [MEDIUM] CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=717084
Please note: this issue affects multiple
Bugzilla
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [epel-5]
bugzilla·2011-06-29·CVSS 5.0
CVE-2011-2501 [MEDIUM] CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [epel-5]
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [epel-5]
epel-5 tracking bug for mingw32-libpng: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
mingw32-libpng-1.2.37-2.el5 has been submitted as an update for Fedora EPEL 5.
https://admin.fedoraproject.org/updates/mingw32-libpng-1.2.37-2.el5
---
mingw32-libpng-1.2.37-3.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/mingw32-libpng-1.2.37-3.el6
---
Package mingw32-libpng-1.2.37-2.el5:
* should fix your issue,
* was pushed to the Fedora EPEL 5 testing repository,
* should be available at your local mirro
Bugzilla
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [epel-6]
bugzilla·2011-06-29·CVSS 5.0
CVE-2011-2501 [MEDIUM] CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [epel-6]
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [epel-6]
epel-6 tracking bug for libpng10: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
mingw32-libpng-1.2.37-3.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/mingw32-libpng-1.2.37-3.el6
---
libpng10-1.0.54-3.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/libpng10-1.0.54-3.el6
---
Package mingw32-libpng-1.2.37-3.el6:
* should fix your issue,
* was pushed to the Fedora EPEL 6 testing repository,
* should be available at your local mirror within two days.
Bugzilla
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+
bugzilla·2011-06-27·CVSS 5.0
CVE-2011-2501 [MEDIUM] CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+
It was reported [1] that the fix for CVE-2004-0421 in libpng was inadvertently reverted during the 1.2.23 development cycle. The original flaw could be used to cause a denial of service via a carefully-crafted PNG image.
This would affect all versions of libpng >=1.2.23, including 1.4.x and 1.5.x.
[1] http://sourceforge.net/mailarchive/forum.php?thread_name=BANLkTikrnU6FJNQYFvwmt78hwpgKPVRd1Q%40mail.gmail.com&forum_name=png-mng-implement
Discussion:
Upstream fix is here:
http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commitdiff;h=65e6d5a34f49acdb362a0625a706c6b914e670af
---
This has been assigned CVE-2011-2501:
http://www.openwall.com/lists/oss-security/2011/06/28/16
---
Created libpng tracking bugs
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=commit%3Bh=65e6d5a34f49acdb362a0625a706c6b914e670afhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062720.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/063118.htmlhttp://secunia.com/advisories/45046http://secunia.com/advisories/45289http://secunia.com/advisories/45405http://secunia.com/advisories/45415http://secunia.com/advisories/45460http://secunia.com/advisories/45486http://secunia.com/advisories/45492http://secunia.com/advisories/49660http://security.gentoo.org/glsa/glsa-201206-15.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.617466http://sourceforge.net/mailarchive/forum.php?thread_name=BANLkTikrnU6FJNQYFvwmt78hwpgKPVRd1Q%40mail.gmail.com&forum_name=png-mng-implementhttp://www.debian.org/security/2011/dsa-2287http://www.mandriva.com/security/advisories?name=MDVSA-2011:151http://www.openwall.com/lists/oss-security/2011/06/27/13http://www.openwall.com/lists/oss-security/2011/06/28/16http://www.redhat.com/support/errata/RHSA-2011-1105.htmlhttp://www.securityfocus.com/bid/48474http://www.ubuntu.com/usn/USN-1175-1https://bugzilla.redhat.com/show_bug.cgi?id=717084https://exchange.xforce.ibmcloud.com/vulnerabilities/68517http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=commit%3Bh=65e6d5a34f49acdb362a0625a706c6b914e670afhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062720.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/063118.htmlhttp://secunia.com/advisories/45046http://secunia.com/advisories/45289http://secunia.com/advisories/45405http://secunia.com/advisories/45415http://secunia.com/advisories/45460http://secunia.com/advisories/45486http://secunia.com/advisories/45492http://secunia.com/advisories/49660http://security.gentoo.org/glsa/glsa-201206-15.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.617466http://sourceforge.net/mailarchive/forum.php?thread_name=BANLkTikrnU6FJNQYFvwmt78hwpgKPVRd1Q%40mail.gmail.com&forum_name=png-mng-implementhttp://www.debian.org/security/2011/dsa-2287http://www.mandriva.com/security/advisories?name=MDVSA-2011:151http://www.openwall.com/lists/oss-security/2011/06/27/13http://www.openwall.com/lists/oss-security/2011/06/28/16http://www.redhat.com/support/errata/RHSA-2011-1105.htmlhttp://www.securityfocus.com/bid/48474http://www.ubuntu.com/usn/USN-1175-1https://bugzilla.redhat.com/show_bug.cgi?id=717084https://exchange.xforce.ibmcloud.com/vulnerabilities/68517
2011-07-17
Published