CVE-2011-2690
published 2011-07-17CVE-2011-2690: Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the…
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.29%
87.1th percentile
Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the png_rgb_to_gray function but not the png_set_expand function, allows remote attackers to overwrite memory with an arbitrary amount of data, and possibly have unspecified other impact, via a crafted PNG image.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| libpng | libpng | >= 1.0.0 < 1.0.55 | 1.0.55 |
| libpng | libpng | >= 1.2.0 < 1.2.45 | 1.2.45 |
| libpng | libpng | >= 1.4.0 < 1.4.8 | 1.4.8 |
| libpng | libpng | >= 1.5.0 < 1.5.4 | 1.5.4 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat8.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libpng vulnerabilities
vendor_ubuntu·2011-07-26·CVSS 6.5
CVE-2011-2692 [MEDIUM] libpng vulnerabilities
Title: libpng vulnerabilities
Summary: Libpng could be made to run programs as your login if it opened a
specially crafted file.
Frank Busse discovered that libpng did not properly handle certain
malformed PNG images. If a user or automated system were tricked into
opening a crafted PNG file, an attacker could cause libpng to crash,
resulting in a denial of service. This issue only affected Ubuntu
10.04 LTS, 10.10, and 11.04. (CVE-2011-2501)
It was discovered that libpng did not properly handle certain malformed PNG
images. If a user or automated system were tricked into opening a crafted
PNG file, an attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2011-2690)
Frank Busse discovered that libpng did no
Red Hat
libpng: buffer overwrite in png_rgb_to_gray
vendor_redhat·2011-07-07·CVSS 8.8
CVE-2011-2690 [HIGH] libpng: buffer overwrite in png_rgb_to_gray
libpng: buffer overwrite in png_rgb_to_gray
Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the png_rgb_to_gray function but not the png_set_expand function, allows remote attackers to overwrite memory with an arbitrary amount of data, and possibly have unspecified other impact, via a crafted PNG image.
Package: libpng (Red Hat Enterprise Linux 4) - Not affected
Package: libpng10 (Red Hat Enterprise Linux 4) - Not affected
GHSA
GHSA-45qx-49q8-7q26: Buffer overflow in libpng 1
ghsa_unreviewed·2022-05-13
CVE-2011-2690 [HIGH] CWE-120 GHSA-45qx-49q8-7q26: Buffer overflow in libpng 1
Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the png_rgb_to_gray function but not the png_set_expand function, allows remote attackers to overwrite memory with an arbitrary amount of data, and possibly have unspecified other impact, via a crafted PNG image.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2690 CVE-2011-2692 libpng various flaws [fedora-all]
bugzilla·2011-07-14·CVSS 8.8
CVE-2011-2690 [HIGH] CVE-2011-2690 CVE-2011-2692 libpng various flaws [fedora-all]
CVE-2011-2690 CVE-2011-2692 libpng various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=720607
Please note: this issue affects multiple supported ve
Bugzilla
CVE-2011-2690 CVE-2011-2692 mingw32-libpng various flaws [epel-5]
bugzilla·2011-07-14·CVSS 8.8
CVE-2011-2690 [HIGH] CVE-2011-2690 CVE-2011-2692 mingw32-libpng various flaws [epel-5]
CVE-2011-2690 CVE-2011-2692 mingw32-libpng various flaws [epel-5]
epel-5 tracking bug for mingw32-libpng: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2011-2692
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=720607,720612
---
All mingw32 packages have been removed from EPEL-5 as per https://fedorahosted.org/rel-eng/ticket/5977
Bugzilla
CVE-2011-2690 CVE-2011-2692 libpng10 various flaws [epel-6]
bugzilla·2011-07-14·CVSS 8.8
CVE-2011-2690 [HIGH] CVE-2011-2690 CVE-2011-2692 libpng10 various flaws [epel-6]
CVE-2011-2690 CVE-2011-2692 libpng10 various flaws [epel-6]
epel-6 tracking bug for libpng10: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2011-2692
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=720607,720612
---
libpng10-1.0.55-1.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/libpng10-1.0.55-1.el6
---
libpng10-1.0.55-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2011-2690 CVE-2011-2692 libpng10 various flaws [fedora-all]
bugzilla·2011-07-14·CVSS 8.8
CVE-2011-2690 [HIGH] CVE-2011-2690 CVE-2011-2692 libpng10 various flaws [fedora-all]
CVE-2011-2690 CVE-2011-2692 libpng10 various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=720607
Please note: this issue affects multiple supported
Bugzilla
CVE-2011-2690 CVE-2011-2692 mingw32-libpng various flaws [fedora-all]
bugzilla·2011-07-14·CVSS 8.8
CVE-2011-2690 [HIGH] CVE-2011-2690 CVE-2011-2692 mingw32-libpng various flaws [fedora-all]
CVE-2011-2690 CVE-2011-2692 mingw32-libpng various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=720607
Please note: this issue affects multiple supp
Bugzilla
CVE-2011-2690 libpng: buffer overwrite in png_rgb_to_gray
bugzilla·2011-07-12·CVSS 8.8
CVE-2011-2690 [HIGH] CVE-2011-2690 libpng: buffer overwrite in png_rgb_to_gray
CVE-2011-2690 libpng: buffer overwrite in png_rgb_to_gray
libpng overwrites unallocated memory when promoting a paletted image with
transparency (one channel) to gray-alpha (two channels), only if the
application calls png_rgb_to_gray() but fails to call png_set_expand().
This bug exists in all released versions of libpng (1.0, 1.2, 1.4 and 1.5).
The data overwritten is entirely controlled by the image data in the PNG file and it is possible to cause any string of data to be written by fabricating an appropriate PNG file. The amount of overwrite is equal to the row length of the original image.
This has been fixed in libpng-1.5.4, libpng-1.4.8, libpng-1.2.45, and libpng-1.0.55.
Discussion:
This has been assigned CVE-2011-2690
---
Created libpng tracking bugs for this issue
Affects:
Bugzilla
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
bugzilla·2011-06-29·CVSS 5.0
CVE-2011-2501 [MEDIUM] CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=717084
Please note: this issue affects multiple
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/063118.htmlhttp://secunia.com/advisories/45046http://secunia.com/advisories/45405http://secunia.com/advisories/45415http://secunia.com/advisories/45460http://secunia.com/advisories/45461http://secunia.com/advisories/45492http://secunia.com/advisories/49660http://security.gentoo.org/glsa/glsa-201206-15.xmlhttp://support.apple.com/kb/HT5002http://www.debian.org/security/2011/dsa-2287http://www.libpng.org/pub/png/libpng.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:151http://www.openwall.com/lists/oss-security/2011/07/13/2http://www.redhat.com/support/errata/RHSA-2011-1104.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1105.htmlhttp://www.securityfocus.com/bid/48660http://www.ubuntu.com/usn/USN-1175-1https://bugzilla.redhat.com/show_bug.cgi?id=720607https://exchange.xforce.ibmcloud.com/vulnerabilities/68538http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/063118.htmlhttp://secunia.com/advisories/45046http://secunia.com/advisories/45405http://secunia.com/advisories/45415http://secunia.com/advisories/45460http://secunia.com/advisories/45461http://secunia.com/advisories/45492http://secunia.com/advisories/49660http://security.gentoo.org/glsa/glsa-201206-15.xmlhttp://support.apple.com/kb/HT5002http://www.debian.org/security/2011/dsa-2287http://www.libpng.org/pub/png/libpng.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:151http://www.openwall.com/lists/oss-security/2011/07/13/2http://www.redhat.com/support/errata/RHSA-2011-1104.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1105.htmlhttp://www.securityfocus.com/bid/48660http://www.ubuntu.com/usn/USN-1175-1https://bugzilla.redhat.com/show_bug.cgi?id=720607https://exchange.xforce.ibmcloud.com/vulnerabilities/68538
2011-07-17
Published