drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in libpng
Name: |
Mehrere Probleme in libpng |
|
ID: |
USN-1175-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 8.04 LTS, Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04 |
|
Datum: |
Di, 26. Juli 2011, 22:49 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2501
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2690
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2692 |
|
Applikationen: |
libpng |
|
Originalnachricht |
--===============9018867239231755047== Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-Yv08OCK/jeczbVIrgl2a"
--=-Yv08OCK/jeczbVIrgl2a Content-Type: text/plain; charset="UTF-8 Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-1175-1 July 26, 2011
libpng vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 11.04 - Ubuntu 10.10 - Ubuntu 10.04 LTS - Ubuntu 8.04 LTS
Summary:
Libpng could be made to run programs as your login if it opened a specially crafted file.
Software Description: - libpng: PNG (Portable Network Graphics) file library
Details:
Frank Busse discovered that libpng did not properly handle certain malformed PNG images. If a user or automated system were tricked into opening a crafted PNG file, an attacker could cause libpng to crash, resulting in a denial of service. This issue only affected Ubuntu 10.04 LTS, 10.10, and 11.04. (CVE-2011-2501)
It was discovered that libpng did not properly handle certain malformed PNG images. If a user or automated system were tricked into opening a crafted PNG file, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2011-2690)
Frank Busse discovered that libpng did not properly handle certain PNG images with invalid sCAL chunks. If a user or automated system were tricked into opening a crafted PNG file, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2011-2692)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 11.04: libpng12-0 1.2.44-1ubuntu3.1
Ubuntu 10.10: libpng12-0 1.2.44-1ubuntu0.1
Ubuntu 10.04 LTS: libpng12-0 1.2.42-1ubuntu2.2
Ubuntu 8.04 LTS: libpng12-0 1.2.15~beta5-3ubuntu0.4
After a standard system update you need to reboot your computer to make all the necessary changes.
References: http://www.ubuntu.com/usn/usn-1175-1 CVE-2011-2501, CVE-2011-2690, CVE-2011-2692
Package Information: https://launchpad.net/ubuntu/+source/libpng/1.2.44-1ubuntu3.1 https://launchpad.net/ubuntu/+source/libpng/1.2.44-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libpng/1.2.42-1ubuntu2.2 https://launchpad.net/ubuntu/+source/libpng/1.2.15~beta5-3ubuntu0.4
--Òv08OCK/jeczbVIrgl2a Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux)
iQIcBAABCgAGBQJOLwK3AAoJEGVp2FWnRL6T2IYP/0fGd+EuxKMHJopcNawwRHEy +vSf+/zJGNKNlmLOoq5/3FATrhHnMZ48IFO2BsaBr6+77c2MLJR1hyNg5Ldle4ab KwORgusiDXC+rGFMGL0VhE3fHZuVG1MhVLhaE083xmGsIYI+03I6PVrAe0LskijD os1PAhuI90E356ungWrCdJGLK2a4n0BHPVatyTXXDLJLH7L2BnZSXg8oK6eFogjn TKEzB2lpBIM73/QtibaxJp9XU+Bzl0kBITUunukzJgH9lb9f3O+RqmCOjdLX20jG 6MSSYpy9Qxl+2WMqlXpKswx4QVrS2Rn6tFwfiMfrkdDw8KpQlXYZt5bJoGE5iuok HifQtFeT/SeqhvLA3uJ+BUnECMA/XAPRlHmoYOx/wujrMpvRKF7fHYvFjpJgVa23 3NUs4W4F7GceG9cu8u2xulJLfT1bVIzDi1s4a4uBXKiyQJtLzfNuASpdmkhqhERP 37/eXJXy6FjGge5I1OhQ7dZMYvctQEUWvVq/eIQZoPPHpGdWx20YFTJ8XPoLyX8X U4vN6UyIPi6LiAfeQKXZd4Kbi2DN81uWUBWB09+asnAuXZtSvgLGdrEo4q/OZjJa ZPy94fvRjKme3cStOEY5XAU5/t82tEiBZ/jCpG7YdM9yglWfMvpOfYUWA3n7WtUL QXCTyM/9oxXdRGTZuwu7 =rhJF -----END PGP SIGNATURE-----
--=-Yv08OCK/jeczbVIrgl2a--
--===============9018867239231755047== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============9018867239231755047==--
|
|
|
|