Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian DSA-2287-1 Critical: Libpng Memory Corruption and DoS Threats

debian
Calendar Grey July 28, 2011
Debian Logo
Debian DSA-2288-1 highlights severe vulnerabilities in OpenSSL that facilitate unauthorized access and potential security breaches.
The PNG library libpng has been affected by several vulnerabilities

Summary

The PNG library libpng has been affected by several vulnerabilities. The
most critical one is the identified as CVE-2011-2690. Using this
vulnerability, an attacker is able to overwrite memory with an
arbitrary amount of data controlled by her via a crafted PNG image.

The other vulnerabilities are less critical and allow an attacker to
cause a crash in the program (denial of service) via a crafted PNG
image.

For the oldstable distribution (lenny), this problem has been fixed in
version 1.2.27-2+lenny5. Due to a technical limitation in the Debian
archive processing scripts, the updated packages cannot be released
in paralell with the packages for Squeeze. They will appear shortly.

For the stable distribution (squeeze), this problem has been fixed in
version 1.2.44-1+squeeze1.

For the unstable distribution (sid), this problem has been fixed in
version 1.2.46-1.

We recommend that you upgrade your libpng packages.

Further information about Debian Security Advisories, how to apply
these updates to y...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: libpng
CVE ID: CVE-2011-2501 CVE-2011-2690 CVE-2011-2691 CVE-2011-2692

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here