4.3
CVSSv2

CVE-2011-2691

Published: 17/07/2011 Updated: 13/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The png_err function in pngerror.c in libpng 1.0.x prior to 1.0.55, 1.2.x prior to 1.2.45, 1.4.x prior to 1.4.8, and 1.5.x prior to 1.5.4 makes a function call using a NULL pointer argument instead of an empty-string argument, which allows remote malicious users to cause a denial of service (application crash) via a crafted PNG image.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libpng libpng

fedoraproject fedora 14

debian debian linux 5.0

debian debian linux 6.0

Vendor Advisories

Debian Bug report logs - #633871 Three security issues Package: libpng; Maintainer for libpng is Anibal Monsalve Salazar <anibal@debianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Thu, 14 Jul 2011 15:36:01 UTC Severity: grave Tags: security Fixed in versions libpng/1246-1, libpng/154- ...
Debian Bug report logs - #632786 CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1223+ Package: libpng; Maintainer for libpng is Anibal Monsalve Salazar <anibal@debianorg>; Reported by: Aníbal Monsalve Salazar <anibal@debianorg> Date: Tue, 5 Jul 2011 23:03:02 UTC Severity: critical Tags: patch, security F ...
The PNG library libpng has been affected by several vulnerabilities The most critical one is the identified as CVE-2011-2690 Using this vulnerability, an attacker is able to overwrite memory with an arbitrary amount of data controlled by her via a crafted PNG image The other vulnerabilities are less critical and allow an attacker to cause a cras ...