6.8
CVSSv2

CVE-2011-2690

Published: 17/07/2011 Updated: 06/08/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in libpng 1.0.x prior to 1.0.55, 1.2.x prior to 1.2.45, 1.4.x prior to 1.4.8, and 1.5.x prior to 1.5.4, when used by an application that calls the png_rgb_to_gray function but not the png_set_expand function, allows remote malicious users to overwrite memory with an arbitrary amount of data, and possibly have unspecified other impact, via a crafted PNG image.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libpng libpng

fedoraproject fedora 14

debian debian linux 5.0

debian debian linux 6.0

canonical ubuntu linux 8.04

canonical ubuntu linux 10.04

canonical ubuntu linux 10.10

canonical ubuntu linux 11.04

Vendor Advisories

Libpng could be made to run programs as your login if it opened a specially crafted file ...
Debian Bug report logs - #633871 Three security issues Package: libpng; Maintainer for libpng is Anibal Monsalve Salazar <anibal@debianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Thu, 14 Jul 2011 15:36:01 UTC Severity: grave Tags: security Fixed in versions libpng/1246-1, libpng/154- ...
Debian Bug report logs - #632786 CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1223+ Package: libpng; Maintainer for libpng is Anibal Monsalve Salazar <anibal@debianorg>; Reported by: Aníbal Monsalve Salazar <anibal@debianorg> Date: Tue, 5 Jul 2011 23:03:02 UTC Severity: critical Tags: patch, security F ...
The PNG library libpng has been affected by several vulnerabilities The most critical one is the identified as CVE-2011-2690 Using this vulnerability, an attacker is able to overwrite memory with an arbitrary amount of data controlled by her via a crafted PNG image The other vulnerabilities are less critical and allow an attacker to cause a cras ...