CVE-2011-3045
published 2012-03-22CVE-2011-3045: Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other…
PriorityP338high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.60%
88.2th percentile
Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 17.0.963.83 | 17.0.963.83 | |
| libpng | libpng | < 1.5.10 | 1.5.10 |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | gluster_storage | — | — |
| redhat | storage | — | — |
| redhat | storage_for_public_cloud | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w4pv-vqp3-f753: Integer signedness error in the png_inflate function in pngrutil
ghsa_unreviewed·2022-05-13·CVSS 6.8
CVE-2011-3045 [MEDIUM] CWE-190 GHSA-w4pv-vqp3-f753: Integer signedness error in the png_inflate function in pngrutil
Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.
Ubuntu
libpng vulnerability
vendor_ubuntu·2012-03-22
CVE-2011-3045 libpng vulnerability
Title: libpng vulnerability
Summary: libpng could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that libpng did not properly process compressed chunks.
If a user or automated system using libpng were tricked into opening a
specially crafted image, an attacker could exploit this to cause a denial
of service or execute code with the privileges of the user invoking the
program.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
libpng: buffer overflow in png_inflate caused by invalid type conversions
vendor_redhat·2012-03-08·CVSS 6.8
CVE-2011-3045 [MEDIUM] libpng: buffer overflow in png_inflate caused by invalid type conversions
libpng: buffer overflow in png_inflate caused by invalid type conversions
Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.
Package: libpng (Red Hat Enterprise Linux 4) - Will not fix
Package: libpng10 (Red Hat Enterprise Linux 4) - Will not fix
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3045 libpng: buffer overflow in png_inflate caused by invalid type conversions [epel-6]
bugzilla·2012-03-09·CVSS 8.8
CVE-2011-3045 [HIGH] CVE-2011-3045 libpng: buffer overflow in png_inflate caused by invalid type conversions [epel-6]
CVE-2011-3045 libpng: buffer overflow in png_inflate caused by invalid type conversions [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/update
Bugzilla
CVE-2011-3045 libpng: buffer overflow in png_inflate caused by invalid type conversions [fedora-all]
bugzilla·2012-03-09·CVSS 8.8
CVE-2011-3045 [HIGH] CVE-2011-3045 libpng: buffer overflow in png_inflate caused by invalid type conversions [fedora-all]
CVE-2011-3045 libpng: buffer overflow in png_inflate caused by invalid type conversions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/up
Bugzilla
CVE-2011-3045 libpng: buffer overflow in png_inflate caused by invalid type conversions [fedora-all]
bugzilla·2012-03-09·CVSS 8.8
CVE-2011-3045 [HIGH] CVE-2011-3045 libpng: buffer overflow in png_inflate caused by invalid type conversions [fedora-all]
CVE-2011-3045 libpng: buffer overflow in png_inflate caused by invalid type conversions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/up
Bugzilla
CVE-2011-3045 libpng: buffer overflow in png_inflate caused by invalid type conversions
bugzilla·2012-03-01·CVSS 8.8
CVE-2011-3045 [HIGH] CVE-2011-3045 libpng: buffer overflow in png_inflate caused by invalid type conversions
CVE-2011-3045 libpng: buffer overflow in png_inflate caused by invalid type conversions
A type conversion flaw leading to an out-of-bounds heap buffer read was found in the way libpng, a library of functions for manipulation PNG image format files, performed expansion of certain iCCP, iTXt, and zTXt PNG image file chunks.
A remote attacker could provide a specially-crafted Portable Network Graphics (PNG) image file, which once opened in an application, linked against libpng, could lead to denial of service or in some cases, execution of arbitrary code with permission of the user running such an application.
Upstream patch:
http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commitdiff;h=a8c319a2b281af68f7ca0e2f9a28ca57b44ceb2b#patch3
Discussion:
This issue affects the v
http://code.google.com/p/chromium/issues/detail?id=116162http://googlechromereleases.blogspot.com/2012/03/stable-channel-update_21.htmlhttp://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=commit%3Bh=a8c319a2b281af68f7ca0e2f9a28ca57b44ceb2bhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/075424.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/075619.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/075981.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/075987.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/076461.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/076731.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2012-03/msg00051.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0407.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0488.htmlhttp://secunia.com/advisories/48320http://secunia.com/advisories/48485http://secunia.com/advisories/48512http://secunia.com/advisories/48554http://secunia.com/advisories/49660http://security.gentoo.org/glsa/glsa-201206-15.xmlhttp://src.chromium.org/viewvc/chrome?view=rev&revision=125311http://www.debian.org/security/2012/dsa-2439http://www.mandriva.com/security/advisories?name=MDVSA-2012:033http://www.securitytracker.com/id?1026823https://bugzilla.redhat.com/show_bug.cgi?id=799000https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14763http://code.google.com/p/chromium/issues/detail?id=116162http://googlechromereleases.blogspot.com/2012/03/stable-channel-update_21.htmlhttp://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=commit%3Bh=a8c319a2b281af68f7ca0e2f9a28ca57b44ceb2bhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/075424.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/075619.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/075981.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/075987.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/076461.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/076731.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2012-03/msg00051.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0407.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0488.htmlhttp://secunia.com/advisories/48320http://secunia.com/advisories/48485http://secunia.com/advisories/48512http://secunia.com/advisories/48554http://secunia.com/advisories/49660http://security.gentoo.org/glsa/glsa-201206-15.xmlhttp://src.chromium.org/viewvc/chrome?view=rev&revision=125311http://www.debian.org/security/2012/dsa-2439http://www.mandriva.com/security/advisories?name=MDVSA-2012:033http://www.securitytracker.com/id?1026823https://bugzilla.redhat.com/show_bug.cgi?id=799000https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14763
2012-03-22
Published