CVE-2011-2692
published 2011-07-17CVE-2011-2692: The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly…
PriorityP338high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
4.23%
90.0th percentile
The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted PNG image that triggers the reading of uninitialized memory.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| libpng | libpng | >= 1.0.0 < 1.0.55 | 1.0.55 |
| libpng | libpng | >= 1.2.0 < 1.2.45 | 1.2.45 |
| libpng | libpng | >= 1.4.0 < 1.4.8 | 1.4.8 |
| libpng | libpng | >= 1.5.0 < 1.5.4 | 1.5.4 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat8.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jggw-3xrj-fwp3: The png_handle_sCAL function in pngrutil
ghsa_unreviewed·2022-05-13
CVE-2011-2692 [HIGH] CWE-119 GHSA-jggw-3xrj-fwp3: The png_handle_sCAL function in pngrutil
The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted PNG image that triggers the reading of uninitialized memory.
Ubuntu
libpng vulnerabilities
vendor_ubuntu·2011-07-26·CVSS 6.5
CVE-2011-2692 [MEDIUM] libpng vulnerabilities
Title: libpng vulnerabilities
Summary: Libpng could be made to run programs as your login if it opened a
specially crafted file.
Frank Busse discovered that libpng did not properly handle certain
malformed PNG images. If a user or automated system were tricked into
opening a crafted PNG file, an attacker could cause libpng to crash,
resulting in a denial of service. This issue only affected Ubuntu
10.04 LTS, 10.10, and 11.04. (CVE-2011-2501)
It was discovered that libpng did not properly handle certain malformed PNG
images. If a user or automated system were tricked into opening a crafted
PNG file, an attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2011-2690)
Frank Busse discovered that libpng did no
Red Hat
libpng: Invalid read when handling empty sCAL chunks
vendor_redhat·2011-07-07·CVSS 8.8
CVE-2011-2692 [HIGH] libpng: Invalid read when handling empty sCAL chunks
libpng: Invalid read when handling empty sCAL chunks
The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted PNG image that triggers the reading of uninitialized memory.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2690 CVE-2011-2692 libpng various flaws [fedora-all]
bugzilla·2011-07-14·CVSS 8.8
CVE-2011-2690 [HIGH] CVE-2011-2690 CVE-2011-2692 libpng various flaws [fedora-all]
CVE-2011-2690 CVE-2011-2692 libpng various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=720607
Please note: this issue affects multiple supported ve
Bugzilla
CVE-2011-2690 CVE-2011-2692 mingw32-libpng various flaws [epel-5]
bugzilla·2011-07-14·CVSS 8.8
CVE-2011-2690 [HIGH] CVE-2011-2690 CVE-2011-2692 mingw32-libpng various flaws [epel-5]
CVE-2011-2690 CVE-2011-2692 mingw32-libpng various flaws [epel-5]
epel-5 tracking bug for mingw32-libpng: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2011-2692
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=720607,720612
---
All mingw32 packages have been removed from EPEL-5 as per https://fedorahosted.org/rel-eng/ticket/5977
Bugzilla
CVE-2011-2690 CVE-2011-2692 libpng10 various flaws [epel-6]
bugzilla·2011-07-14·CVSS 8.8
CVE-2011-2690 [HIGH] CVE-2011-2690 CVE-2011-2692 libpng10 various flaws [epel-6]
CVE-2011-2690 CVE-2011-2692 libpng10 various flaws [epel-6]
epel-6 tracking bug for libpng10: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2011-2692
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=720607,720612
---
libpng10-1.0.55-1.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/libpng10-1.0.55-1.el6
---
libpng10-1.0.55-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2011-2690 CVE-2011-2692 libpng10 various flaws [fedora-all]
bugzilla·2011-07-14·CVSS 8.8
CVE-2011-2690 [HIGH] CVE-2011-2690 CVE-2011-2692 libpng10 various flaws [fedora-all]
CVE-2011-2690 CVE-2011-2692 libpng10 various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=720607
Please note: this issue affects multiple supported
Bugzilla
CVE-2011-2690 CVE-2011-2692 mingw32-libpng various flaws [fedora-all]
bugzilla·2011-07-14·CVSS 8.8
CVE-2011-2690 [HIGH] CVE-2011-2690 CVE-2011-2692 mingw32-libpng various flaws [fedora-all]
CVE-2011-2690 CVE-2011-2692 mingw32-libpng various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=720607
Please note: this issue affects multiple supp
Bugzilla
CVE-2011-2692 libpng: Invalid read when handling empty sCAL chunks
bugzilla·2011-07-12·CVSS 8.8
CVE-2011-2692 [HIGH] CVE-2011-2692 libpng: Invalid read when handling empty sCAL chunks
CVE-2011-2692 libpng: Invalid read when handling empty sCAL chunks
It was found that libpng read uninitialized memory when it encountered a
sCAL chunk that is empty, and improperly handles a sCAL chunk that lacks
the terminating zero between the two strings that it conveys.
This was fixed in libpng-1.5.4, libpng-1.4.8, libpng-1.2.45,
and libpng-1.0.55.
Patch:
http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commitdiff;h=61a2d8a2a7b03023e63eae9a3e64607aaaa6d339
Discussion:
This has been assigned CVE-2011-2692
---
This is also CERT VU#819894:
http://www.kb.cert.org/vuls/id/819894
---
Created libpng tracking bugs for this issue
Affects: fedora-all [bug 721307]
---
Created libpng10 tracking bugs for this issue
Affects: fedora-all [bug 721309]
Affects: epel-6 [bu
Bugzilla
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
bugzilla·2011-06-29·CVSS 5.0
CVE-2011-2501 [MEDIUM] CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+ [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=717084
Please note: this issue affects multiple
http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=commit%3Bh=61a2d8a2a7b03023e63eae9a3e64607aaaa6d339http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2012/May/msg00001.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/063118.htmlhttp://secunia.com/advisories/45046http://secunia.com/advisories/45405http://secunia.com/advisories/45415http://secunia.com/advisories/45445http://secunia.com/advisories/45460http://secunia.com/advisories/45461http://secunia.com/advisories/45492http://secunia.com/advisories/49660http://security.gentoo.org/glsa/glsa-201206-15.xmlhttp://sourceforge.net/mailarchive/forum.php?thread_name=003101cc2790%24fb5d6e80%24f2184b80%24%40acm.org&forum_name=png-mng-implementhttp://support.apple.com/kb/HT5002http://support.apple.com/kb/HT5281http://www.debian.org/security/2011/dsa-2287http://www.kb.cert.org/vuls/id/819894http://www.libpng.org/pub/png/libpng.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:151http://www.openwall.com/lists/oss-security/2011/07/13/2http://www.redhat.com/support/errata/RHSA-2011-1103.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1104.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1105.htmlhttp://www.securityfocus.com/bid/48618http://www.ubuntu.com/usn/USN-1175-1https://bugzilla.redhat.com/show_bug.cgi?id=720612https://exchange.xforce.ibmcloud.com/vulnerabilities/68536http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=commit%3Bh=61a2d8a2a7b03023e63eae9a3e64607aaaa6d339http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2012/May/msg00001.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/063118.htmlhttp://secunia.com/advisories/45046http://secunia.com/advisories/45405http://secunia.com/advisories/45415http://secunia.com/advisories/45445http://secunia.com/advisories/45460http://secunia.com/advisories/45461http://secunia.com/advisories/45492http://secunia.com/advisories/49660http://security.gentoo.org/glsa/glsa-201206-15.xmlhttp://sourceforge.net/mailarchive/forum.php?thread_name=003101cc2790%24fb5d6e80%24f2184b80%24%40acm.org&forum_name=png-mng-implementhttp://support.apple.com/kb/HT5002http://support.apple.com/kb/HT5281http://www.debian.org/security/2011/dsa-2287http://www.kb.cert.org/vuls/id/819894http://www.libpng.org/pub/png/libpng.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:151http://www.openwall.com/lists/oss-security/2011/07/13/2http://www.redhat.com/support/errata/RHSA-2011-1103.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1104.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1105.htmlhttp://www.securityfocus.com/bid/48618http://www.ubuntu.com/usn/USN-1175-1https://bugzilla.redhat.com/show_bug.cgi?id=720612https://exchange.xforce.ibmcloud.com/vulnerabilities/68536
2011-07-17
Published