CVE-2011-2690: Buffer Overflow

Published Jul 7, 2011
·
Updated

Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the pngrgbtogray function but not the pngsetexpand function, allows remote attackers to overwrite memory with an arbitrary amount of data, and possibly have unspecified other impact, via a crafted PNG image.

Other sources

libpng overwrites unallocated memory when promoting a paletted image with transparency (one channel) to gray-alpha (two channels), only if the application calls pngrgbtogray() but fails to call pngsetexpand().

This bug exists in all released versions of libpng (1.0, 1.2, 1.4 and 1.5). The data overwritten is entirely controlled by the image data in the PNG file and it is possible to cause any string of data to be written by fabricating an appropriate PNG file. The amount of overwrite is equal to the row length of the original image.

This has been fixed in libpng-1.5.4, libpng-1.4.8, libpng-1.2.45, and libpng-1.0.55.

Red Hat

Affected Software

13 affected componentsFixes available
redhat/libpng<2:1.2.10-7.1.el5_7.5
2:1.2.10-7.1.el5_7.5
redhat/libpng<2:1.2.46-1.el6_1
2:1.2.46-1.el6_1
libpng LIBPNG>=1.5.0<1.5.4
libpng LIBPNG>=1.4.0<1.4.8
libpng LIBPNG>=1.2.0<1.2.45
libpng LIBPNG>=1.0.0<1.0.55
Fedoraproject Fedora=14
Debian Debian Linux=5.0
Debian Debian Linux=6.0
Canonical Ubuntu Linux=10.10
Canonical Ubuntu Linux=11.04
Canonical Ubuntu Linux=10.04
Canonical Ubuntu Linux=8.04

Event History

Jul 7, 2011
CVE Published
12:00 AM
Jul 12, 2011
Data Sourced
via Red Hat·09:09 AM
DescriptionSeverityAffected Software
Jul 17, 2011
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2011-2690?

CVE-2011-2690 is considered to have a critical severity level due to its potential for remote code execution.

2

How do I fix CVE-2011-2690?

To fix CVE-2011-2690, update to the recommended versions of libpng: 1.0.55 or higher, 1.2.45 or higher, 1.4.8 or higher, or 1.5.4 or higher.

3

Which versions of libpng are affected by CVE-2011-2690?

CVE-2011-2690 affects libpng versions 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4.

4

Can CVE-2011-2690 lead to data loss?

Yes, CVE-2011-2690 can potentially lead to data loss by allowing attackers to overwrite memory.

5

Is CVE-2011-2690 related to a specific function in libpng?

CVE-2011-2690 specifically arises when an application calls the png_rgb_to_gray function without calling png_set_expand.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203