FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-3048

This CVE name corresponds to:

Entered Topic
2012-04-08 png -- memory corruption/possible remote code execution

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-3048
Phase Assigned(20110809)

Description

The png_set_text_2 function in pngset.c in libpng 1.0.x before 1.0.59, 1.2.x before 1.2.49, 1.4.x before 1.4.11, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted text chunk in a PNG image file, which triggers a memory allocation failure that is not properly handled, leading to a heap-based buffer overflow.

References

Source Reference
CONFIRM http://www.libpng.org/pub/png/libpng.html
CONFIRM http://www.libpng.org/pub/png/src/libpng-1.5.10-README.txt
CONFIRM http://support.apple.com/kb/HT5501
CONFIRM http://support.apple.com/kb/HT5503
APPLE APPLE-SA-2012-09-19-1
APPLE APPLE-SA-2012-09-19-2
DEBIAN DSA-2446
FEDORA FEDORA-2012-5515
FEDORA FEDORA-2012-5518
FEDORA FEDORA-2012-5526
FEDORA FEDORA-2012-4902
FEDORA FEDORA-2012-5079
FEDORA FEDORA-2012-5080
GENTOO GLSA-201206-15
REDHAT RHSA-2012:0523
UBUNTU USN-1417-1
BID 52830
OSVDB 80822
SECTRACK 1026879
SECUNIA 48587
SECUNIA 48644
SECUNIA 48665
SECUNIA 48721
SECUNIA 48983
SECUNIA 49660
XF libpng-pngsettext2-code-execution(74494)