CVE-2011-0408
Published: 18 January 2011
pngrtran.c in libpng 1.5.x before 1.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted palette-based PNG image that triggers a buffer overflow, related to the png_do_expand_palette function, the png_do_rgb_to_gray function, and an integer underflow. NOTE: some of these details are obtained from third party information.
Notes
Author | Note |
---|---|
mdeslaur | libpng 1.5.x only, so not affected |
Priority
Status
Package | Release | Status |
---|---|---|
chromium-browser Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Does not exist
|
|
karmic |
Does not exist
|
|
lucid |
Not vulnerable
|
|
maverick |
Not vulnerable
|
|
upstream |
Not vulnerable
|
|
firefox Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Not vulnerable
|
|
karmic |
Does not exist
|
|
lucid |
Not vulnerable
|
|
maverick |
Not vulnerable
|
|
upstream |
Not vulnerable
|
|
libpng Launchpad, Ubuntu, Debian |
dapper |
Not vulnerable
(1.2.8rel-5ubuntu0.6)
|
hardy |
Not vulnerable
(1.2.15~beta5-3ubuntu0.3)
|
|
karmic |
Not vulnerable
(1.2.37-1ubuntu0.2)
|
|
lucid |
Not vulnerable
(1.2.42-1ubuntu2.1)
|
|
maverick |
Not vulnerable
(1.2.44-1)
|
|
upstream |
Released
(1.5.1)
|
|
Patches: upstream: ftp://ftp.simplesystems.org/pub/png-group/src/libpng-1.5.1beta01-1.5.0-diff.txt |