Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 20.04: USN-4509-2 Important: OpenSSL Security Vulnerability

ubuntu
Calendar Grey July 26, 2011
Scroller Ubuntu
Ubuntu has released a security notice addressing vulnerabilities in libpng that could let attackers execute arbitrary code or trigger a denial of service with specially crafted PNG files
Libpng could be made to run programs as your login if it opened a specially crafted file.

Summary

Libpng could be made to run programs as your login if it opened a

specially crafted file.

Software Description:

- libpng: PNG (Portable Network Graphics) file library

Details:

Frank Busse discovered that libpng did not properly handle certain

malformed PNG images. If a user or automated system were tricked into

opening a crafted PNG file, an attacker could cause libpng to crash,

resulting in a denial of service. This issue only affected Ubuntu

10.04 LTS, 10.10, and 11.04. (CVE-2011-2501)

It was discovered that libpng did not properly handle certain malformed PNG

images. If a user or automated system were tricked into opening a crafted

PNG file, an attacker could cause a denial of service or possibly execute

arbitrary code with the privileges of the user invoking the program.

(CVE-2011-2690)

Frank Busse discovered that libpng did not properly handle certain PNG

images with invalid sCAL chunks. If a user or automated system were tricked

into opening a craf...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
  libpng12-0                      1.2.44-1ubuntu3.1

Ubuntu 10.10:
  libpng12-0                      1.2.44-1ubuntu0.1

Ubuntu 10.04 LTS:
  libpng12-0                      1.2.42-1ubuntu2.2

Ubuntu 8.04 LTS:
  libpng12-0                      1.2.15~beta5-3ubuntu0.4

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1175-1

CVE-2011-2501, CVE-2011-2690, CVE-2011-2692

Severity
important
Lowest
Low
Medium
High
Critical

July 26, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.