CVE-2011-2501

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
17/07/2011
Last modified:
11/04/2025

Description

The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a CVE-2004-0421 regression. NOTE: this is called an off-by-one error by some sources.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* 1.0.0 (including) 1.0.55 (excluding)
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* 1.2.0 (including) 1.2.45 (excluding)
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* 1.4.0 (including) 1.4.8 (excluding)
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* 1.5.0 (including) 1.5.4 (excluding)
cpe:2.3:o:fedoraproject:fedora:14:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.04:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools