VDB
CVE-2011-2501
CVE-2011-2501
PUBLISHED
CVSS 4.300000190734863 MEDIUM
The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a CVE-2004-0421 regression. NOTE: this is called an off-by-one error by some sources.
EPSS 3.48% · 88.0th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
3.48%
88.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| debian | debian_linux | 5.0, 6.0 |
| fedoraproject | fedora | 14 |
| n/a | n/a | * |
| libpng | libpng | 1.5.0, 1.0.0, 1.2.0 |
| canonical | ubuntu_linux | 10.04, 8.04, 10.10 |
Timeline
- Jul 17, 2011 CVE Published
- Aug 6, 2020 CVE Updated
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- USN-1175-1 vendor-advisory
- 48474 vdb
- SSA:2011-210-01 vendor-advisory
- FEDORA-2011-9336 vendor-advisory
- 45492 third-party-advisory
- MDVSA-2011:151 vendor-advisory
- libpng-pngerror-dos(68517) vdb
- http://sourceforge.net/mailarchive/forum.php?thread_name=BANLkTikrnU6FJNQYFvwmt78hwpgKPVRd1Q%40mail.gmail.com&forum_name=png-mng-implement url
- https://nvd.nist.gov/vuln/detail/CVE-2011-2501 advisory
- http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commit;h=65e6d5a34f49acdb362a0625a706c6b914e670af url
- http://secunia.com/advisories/45415 url
- http://secunia.com/advisories/45460 url
- http://secunia.com/advisories/49660 url
- http://www.openwall.com/lists/oss-security/2011/06/28/16 url
- http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062720.html mailing_list
- http://secunia.com/advisories/45405 technical
- http://secunia.com/advisories/45486 technical
- http://security.gentoo.org/glsa/glsa-201206-15.xml advisory
- http://www.debian.org/security/2011/dsa-2287 advisory
- http://www.redhat.com/support/errata/RHSA-2011-1105.html technical
…and 5 more