First published: Wed Jul 11 2018(Updated: )
Patrick Keshishian discovered that libpng incorrectly handled certain PNG files. An attacker could possibly use this to cause a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10087) Thuan Pham discovered that libpng incorrectly handled certain PNG files. An attacker could possibly use this to cause a denial of service. This issue only affected Ubuntu 17.10 and Ubuntu 18.04 LTS. (CVE-2018-13785)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libpng16-16 | <1.6.34-1ubuntu0.18.04.1 | 1.6.34-1ubuntu0.18.04.1 |
=18.04 | ||
All of | ||
ubuntu/libpng16-16 | <1.6.34-1ubuntu0.17.10.1 | 1.6.34-1ubuntu0.17.10.1 |
=17.10 | ||
All of | ||
ubuntu/libpng12-0 | <1.2.54-1ubuntu1.1 | 1.2.54-1ubuntu1.1 |
=16.04 | ||
All of | ||
ubuntu/libpng12-0 | <1.2.50-1ubuntu2.14.04.3 | 1.2.50-1ubuntu2.14.04.3 |
=14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-3712-1 has a severity rating of moderate.
libpng incorrectly handles certain PNG files, which can lead to a denial of service.
USN-3712-1 affects Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 17.10, and Ubuntu 18.04.
The remedy for USN-3712-1 is to upgrade to libpng version 1.6.34-1ubuntu0.18.04.1 for Ubuntu 18.04, 1.6.34-1ubuntu0.17.10.1 for Ubuntu 17.10, 1.2.54-1ubuntu1.1 for Ubuntu 16.04, and 1.2.50-1ubuntu2.14.04.3 for Ubuntu 14.04.
More information about USN-3712-1 can be found at the following links: [CVE-2016-10087](https://ubuntu.com/security/CVE-2016-10087), [CVE-2018-13785](https://ubuntu.com/security/CVE-2018-13785), [USN-3712-2](https://ubuntu.com/security/notices/USN-3712-2).