CVE-2011-2501

Publication date 17 July 2011

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

6.5 · Medium

Score breakdown

The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a CVE-2004-0421 regression. NOTE: this is called an off-by-one error by some sources.

Read the notes from the security team

Status

Package Ubuntu Release Status
chromium-browser 12.04 LTS precise
Not affected
11.10 oneiric
Fixed 14.0.835.202~r103287-0ubuntu1
11.04 natty
Fixed 14.0.835.202~r103287-0ubuntu0.11.04.1
10.10 maverick
Fixed 14.0.835.202~r103287-0ubuntu0.10.10.1
10.04 LTS lucid
Fixed 14.0.835.202~r103287-0ubuntu0.10.04.2
8.04 LTS hardy Not in release
firefox 12.04 LTS precise
Fixed 8.0~b4+build1-0ubuntu2
11.10 oneiric
Fixed 8.0+build1-0ubuntu0.11.10.1
11.04 natty
Fixed 8.0+build1-0ubuntu0.11.04.1
10.10 maverick Ignored end of life
10.04 LTS lucid
Fixed 10.0+build1-0ubuntu0.10.04.2
8.04 LTS hardy Ignored end of life
libpng 12.04 LTS precise
Not affected
11.10 oneiric
Not affected
11.04 natty
Fixed 1.2.44-1ubuntu3.1
10.10 maverick
Fixed 1.2.44-1ubuntu0.1
10.04 LTS lucid
Fixed 1.2.42-1ubuntu2.2
8.04 LTS hardy
Not affected

Notes


mdeslaur

re-introduced in 1.2.23


jdstrand

firefox 3.6.23 has 1.2.35 and 7.0.1 has 1.4.7


micahg

firefox 8 will have 1.4.8

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
libpng

Severity score breakdown

Parameter Value
Base score 6.5 · Medium
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

References

Related Ubuntu Security Notices (USN)

Other references