cbcvebase.
CVE-2011-3026
published 2012-02-16

CVE-2011-3026: Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified…

PriorityP344medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
73.35%
99.4th percentile
Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
appleiphone_os< 6.06.0
applemac_os_x
applemac_os_x>= 10.7.0 < 10.7.510.7.5
applemac_os_x_server
applemac_os_x_server>= 10.7.0 < 10.7.510.7.5
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
googlechrome< 17.0.963.5617.0.963.56
googlechrome< 17.0.963.8317.0.963.83
libpnglibpng< 1.5.101.5.10
opensuseopensuse
opensuseopensuse
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
redhatgluster_storage
redhatstorage
redhatstorage_for_public_cloud

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered via a specially crafted PNG image that causes an integer overflow/truncation during chunk decompression in libpng's png_decompress_chunk function, leading to a heap buffer overflow. Detection should focus on malformed PNG files with anomalous chunk decompression size fields.
  • The vulnerable function is png_decompress_chunk in libpng. Network/endpoint detection should flag processing of PNG files through this code path in affected versions of libpng (before the fix in Google Chrome 17.0.963.56).
  • Affected applications include Google Chrome (before 17.0.963.56), Firefox, Thunderbird, and Xulrunner. Monitor these processes for crashes or unexpected code execution when handling PNG image files.
  • ·The attack vector involves 'unknown vectors' per NVD; the specific PNG chunk structure that triggers the integer truncation is not publicly detailed in these sources, limiting precise signature creation.
  • ·CVE-2011-3026 (png_decompress_chunk heap overflow) is a distinct vulnerability from CVE-2011-3045 (png_inflate signedness error in pngrutil.c); do not conflate detection rules for the two.

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_ubuntu9.3CRITICAL
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.