Home[1] Files[2] News[3] Contact[4] Add New[5]
- Ubuntu Security Notice USN-5432-1[6]
- Authored by Ubuntu[7] | Site security.ubuntu.com[8]
-
Ubuntu Security Notice 5432-1 - It was discovered that libpng incorrectly handled memory when parsing certain PNG files. If a user or automated system were tricked into opening a specially crafted PNG file, an attacker could use this issue to cause libpng to crash, resulting in a denial of service, or possible execute arbitrary code. Zhengxiong Luo discovered that libpng incorrectly handled memory when parsing certain PNG files. If a user or automated system were tricked into opening a specially crafted PNG file, an attacker could use this issue to cause libpng to crash, resulting in a denial of service, or possible execute arbitrary code.
- systems | linux[9], ubuntu[10]
- advisories | CVE-2017-12652[11], CVE-2018-14048[12]
- SHA-256 |
54ca6d5730b37e6ead16f7d5e371061160c7f46a81e138b8550d769c11bfd6ea - Download[13] | Favorite[14] | View[15]
Change Mirror[16] Download[17]
==========================================================================
Ubuntu Security Notice USN-5432-1
May 23, 2022
libpng vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 ESM
Summary:
Several security issues were fixed in libpng.
Software Description:
- libpng: PNG (Portable Network Graphics) file library
Details:
It was discovered that libpng incorrectly handled memory when parsing
certain PNG files. If a user or automated system were tricked into opening
a specially crafted PNG file, an attacker could use this issue to cause
libpng to crash, resulting in a denial of service, or possible execute
arbitrary code. (CVE-2017-12652)
Zhengxiong Luo discovered that libpng incorrectly handled memory when parsing
certain PNG files. If a user or automated system were tricked into opening
a specially crafted PNG file, an attacker could use this issue to cause
libpng to crash, resulting in a denial of service, or possible execute
arbitrary code. (CVE-2018-14048)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 ESM:
libpng12-0 1.2.54-1ubuntu1.1+esm1
libpng12-dev 1.2.54-1ubuntu1.1+esm1
libpng3 1.2.54-1ubuntu1.1+esm1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5432-1
CVE-2017-12652, CVE-2018-14048
File Tags
- ActiveX[22] (932)
- Advisory[23] (77,416)
- Arbitrary[24] (15,086)
- BBS[25] (2,859)
- Bypass[26] (1,562)
- CGI[27] (1,011)
- Code Execution[28] (6,651)
- Conference[29] (668)
- Cracker[30] (797)
- CSRF[31] (3,270)
- DoS[32] (21,796)
- Encryption[33] (2,330)
- Exploit[34] (49,765)
- File Inclusion[35] (4,146)
- File Upload[36] (942)
- Firewall[37] (821)
- Info Disclosure[38] (2,546)
- Intrusion Detection[39] (851)
- Java[40] (2,781)
- JavaScript[41] (793)
- Kernel[42] (6,015)
- Local[43] (13,990)
- Magazine[44] (586)
- Overflow[45] (12,140)
- Perl[46] (1,410)
- PHP[47] (5,039)
- Proof of Concept[48] (2,278)
- Protocol[49] (3,299)
- Python[50] (1,394)
- Remote[51] (29,641)
- Root[52] (3,445)
- Ruby[53] (574)
- Scanner[54] (1,630)
- Security Tool[55] (7,679)
- Shell[56] (3,059)
- Shellcode[57] (1,202)
- Sniffer[58] (880)
- Spoof[59] (2,082)
- SQL Injection[60] (15,997)
- TCP[61] (2,352)
- Trojan[62] (672)
- UDP[63] (866)
- Virus[64] (659)
- Vulnerability[65] (30,412)
- Web[66] (8,997)
- Whitepaper[67] (3,712)
- x86[68] (942)
- XSS[69] (17,304)
- Other[70]
File Archives
- May 2022[71]
- April 2022[72]
- March 2022[73]
- February 2022[74]
- January 2022[75]
- December 2021[76]
- November 2021[77]
- October 2021[78]
- September 2021[79]
- August 2021[80]
- July 2021[81]
- June 2021[82]
- Older[83]
Systems
- AIX[84] (426)
- Apple[85] (1,883)
- BSD[86] (368)
- CentOS[87] (55)
- Cisco[88] (1,912)
- Debian[89] (5,948)
- Fedora[90] (1,690)
- FreeBSD[91] (1,241)
- Gentoo[92] (4,152)
- HPUX[93] (878)
- iOS[94] (318)
- iPhone[95] (108)
- IRIX[96] (220)
- Juniper[97] (67)
- Linux[98] (42,105)
- Mac OS X[99] (683)
- Mandriva[100] (3,105)
- NetBSD[101] (255)
- OpenBSD[102] (478)
- RedHat[103] (11,497)
- Slackware[104] (941)
- Solaris[105] (1,607)
- SUSE[106] (1,444)
- Ubuntu[107] (7,787)
- UNIX[108] (9,060)
- UnixWare[109] (185)
- Windows[110] (6,405)
- Other[111]
- Services
- Security Services[122]
- Hosting By
- Rokasec[123]
Read more https://packetstormsecurity.com/files/167237/USN-5432-1.txt


