Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in libpng
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in libpng
ID: USN-1175-1
Distribution: Ubuntu
Plattformen: Ubuntu 8.04 LTS, Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04
Datum: Di, 26. Juli 2011, 22:49
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2501
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2690
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2692
Applikationen: libpng

Originalnachricht


--===============9018867239231755047==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature"; boundary="=-Yv08OCK/jeczbVIrgl2a"


--=-Yv08OCK/jeczbVIrgl2a
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1175-1
July 26, 2011

libpng vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.04
- Ubuntu 10.10
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

Libpng could be made to run programs as your login if it opened a
specially crafted file.

Software Description:
- libpng: PNG (Portable Network Graphics) file library

Details:

Frank Busse discovered that libpng did not properly handle certain
malformed PNG images. If a user or automated system were tricked into
opening a crafted PNG file, an attacker could cause libpng to crash,
resulting in a denial of service. This issue only affected Ubuntu
10.04 LTS, 10.10, and 11.04. (CVE-2011-2501)

It was discovered that libpng did not properly handle certain malformed PNG
images. If a user or automated system were tricked into opening a crafted
PNG file, an attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2011-2690)

Frank Busse discovered that libpng did not properly handle certain PNG
images with invalid sCAL chunks. If a user or automated system were tricked
into opening a crafted PNG file, an attacker could cause a denial of
service or possibly execute arbitrary code with the privileges of the user
invoking the program. (CVE-2011-2692)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
libpng12-0 1.2.44-1ubuntu3.1

Ubuntu 10.10:
libpng12-0 1.2.44-1ubuntu0.1

Ubuntu 10.04 LTS:
libpng12-0 1.2.42-1ubuntu2.2

Ubuntu 8.04 LTS:
libpng12-0 1.2.15~beta5-3ubuntu0.4

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1175-1
CVE-2011-2501, CVE-2011-2690, CVE-2011-2692

Package Information:
https://launchpad.net/ubuntu/+source/libpng/1.2.44-1ubuntu3.1
https://launchpad.net/ubuntu/+source/libpng/1.2.44-1ubuntu0.1
https://launchpad.net/ubuntu/+source/libpng/1.2.42-1ubuntu2.2
https://launchpad.net/ubuntu/+source/libpng/1.2.15~beta5-3ubuntu0.4



--Òv08OCK/jeczbVIrgl2a
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJOLwK3AAoJEGVp2FWnRL6T2IYP/0fGd+EuxKMHJopcNawwRHEy
+vSf+/zJGNKNlmLOoq5/3FATrhHnMZ48IFO2BsaBr6+77c2MLJR1hyNg5Ldle4ab
KwORgusiDXC+rGFMGL0VhE3fHZuVG1MhVLhaE083xmGsIYI+03I6PVrAe0LskijD
os1PAhuI90E356ungWrCdJGLK2a4n0BHPVatyTXXDLJLH7L2BnZSXg8oK6eFogjn
TKEzB2lpBIM73/QtibaxJp9XU+Bzl0kBITUunukzJgH9lb9f3O+RqmCOjdLX20jG
6MSSYpy9Qxl+2WMqlXpKswx4QVrS2Rn6tFwfiMfrkdDw8KpQlXYZt5bJoGE5iuok
HifQtFeT/SeqhvLA3uJ+BUnECMA/XAPRlHmoYOx/wujrMpvRKF7fHYvFjpJgVa23
3NUs4W4F7GceG9cu8u2xulJLfT1bVIzDi1s4a4uBXKiyQJtLzfNuASpdmkhqhERP
37/eXJXy6FjGge5I1OhQ7dZMYvctQEUWvVq/eIQZoPPHpGdWx20YFTJ8XPoLyX8X
U4vN6UyIPi6LiAfeQKXZd4Kbi2DN81uWUBWB09+asnAuXZtSvgLGdrEo4q/OZjJa
ZPy94fvRjKme3cStOEY5XAU5/t82tEiBZ/jCpG7YdM9yglWfMvpOfYUWA3n7WtUL
QXCTyM/9oxXdRGTZuwu7
=rhJF
-----END PGP SIGNATURE-----

--=-Yv08OCK/jeczbVIrgl2a--



--===============9018867239231755047==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============9018867239231755047==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung