Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Ubuntu 11.10: USN-1500-1 Critical: OpenSSL Security Update

Ubuntu Large Esm H500
libpng could be made to crash or run programs as your login if it opened a specially crafted file.
=========================================================================Ubuntu Security Notice USN-1402-1
March 22, 2012

libpng vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.10
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

libpng could be made to crash or run programs as your login if it
opened a specially crafted file.

Software Description:
- libpng: PNG (Portable Network Graphics) file library

Details:

It was discovered that libpng did not properly process compressed chunks.
If a user or automated system using libpng were tricked into opening a
specially crafted image, an attacker could exploit this to cause a denial
of service or execute code with the privileges of the user invoking the
program.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  libpng12-0                      1.2.46-3ubuntu1.2

Ubuntu 11.04:
  libpng12-0                      1.2.44-1ubuntu3.3

Ubuntu 10.10:
  libpng12-0                      1.2.44-1ubuntu0.3

Ubuntu 10.04 LTS:
  libpng12-0                      1.2.42-1ubuntu2.4

Ubuntu 8.04 LTS:
  libpng12-0                      1.2.15~beta5-3ubuntu0.6

After a standard system update you need to restart your session to make all
the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-1402-1
  CVE-2011-3045

Package Information:
  https://launchpad.net/ubuntu/+source/libpng/1.2.46-3ubuntu1.2
  https://launchpad.net/ubuntu/+source/libpng/1.2.44-1ubuntu3.3
  https://launchpad.net/ubuntu/+source/libpng/1.2.44-1ubuntu0.3
  https://launchpad.net/ubuntu/+source/libpng/1.2.42-1ubuntu2.4
  https://launchpad.net/ubuntu/+source/libpng/1.2.15~beta5-3ubuntu0.6


Ubuntu 11.10: USN-1500-1 Critical: OpenSSL Security Update

ubuntu
Calendar Grey March 22, 2012
Dist Ubuntu Esm H88
A vulnerability in libpng may lead to system crashes or unintended execution of code when handling images on Ubuntu. An update is strongly advised.
libpng could be made to crash or run programs as your login if it opened a specially crafted file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: libpng12-0 1.2.46-3ubuntu1.2 Ubuntu 11.04: libpng12-0 1.2.44-1ubuntu3.3 Ubuntu 10.10: libpng12-0 1.2.44-1ubuntu0.3 Ubuntu 10.04 LTS: libpng12-0 1.2.42-1ubuntu2.4 Ubuntu 8.04 LTS: libpng12-0 1.2.15~beta5-3ubuntu0.6 After a standard system update you need to restart your session to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1402-1

CVE-2011-3045

Severity
critical
Lowest
Low
Medium
High
Critical

March 22, 2012

Package Information

https://launchpad.net/ubuntu/+source/libpng/1.2.46-3ubuntu1.2 https://launchpad.net/ubuntu/+source/libpng/1.2.44-1ubuntu3.3 https://launchpad.net/ubuntu/+source/libpng/1.2.44-1ubuntu0.3 https://launchpad.net/ubuntu/+source/libpng/1.2.42-1ubuntu2.4 https://launchpad.net/ubuntu/+source/libpng/1.2.15~beta5-3ubuntu0.6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here