CVE-2011-3026

Publication date 16 February 2012

Last updated 24 July 2024


Ubuntu priority

Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.

Read the notes from the security team

Status

Package Ubuntu Release Status
chromium-browser 11.10 oneiric
Not affected
11.04 natty
Not affected
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy Not in release
firefox 11.10 oneiric
Fixed 10.0.2+build1-0ubuntu0.11.10.1
11.04 natty
Fixed 10.0.2+build1-0ubuntu0.11.04.1
10.10 maverick
Fixed 10.0.2+build1-0ubuntu0.10.10.1
10.04 LTS lucid
Fixed 10.0.2+build1-0ubuntu0.10.04.1
8.04 LTS hardy Ignored end of life
libpng 11.10 oneiric
Fixed 1.2.46-3ubuntu1.1
11.04 natty
Fixed 1.2.44-1ubuntu3.2
10.10 maverick
Fixed 1.2.44-1ubuntu0.2
10.04 LTS lucid
Fixed 1.2.42-1ubuntu2.3
8.04 LTS hardy
Fixed 1.2.15~beta5-3ubuntu0.5
thunderbird 11.10 oneiric
Fixed 11.0+build1-0ubuntu0.11.10.1
11.04 natty
Fixed 3.1.19+build1+nobinonly-0ubuntu0.11.04.1
10.10 maverick
Fixed 3.1.19+build1+nobinonly-0ubuntu0.10.10.1
10.04 LTS lucid
Fixed 3.1.19+build1+nobinonly-0ubuntu0.10.04.1
8.04 LTS hardy Ignored end of life
xulrunner-1.9.2 11.10 oneiric Not in release
11.04 natty
Fixed 1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1
10.10 maverick
Fixed 1.9.2.27+build1+nobinonly-0ubuntu0.10.10.1
10.04 LTS lucid
Fixed 1.9.2.27+build1+nobinonly-0ubuntu0.10.04.1
8.04 LTS hardy Ignored end of life

Notes


jdstrand

https://ubuntu.com/security/notices/USN-1400-3 had the fix for thunderbird but it wasn't included

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
libpng

References

Related Ubuntu Security Notices (USN)

    • USN-1367-1
    • libpng vulnerabilities
    • 16 February 2012
    • USN-1367-3
    • Thunderbird vulnerability
    • 17 February 2012
    • USN-1367-4
    • Xulrunner vulnerability
    • 17 February 2012
    • USN-1367-2
    • Firefox vulnerability
    • 17 February 2012

Other references