Lucene search

K
ubuntuUbuntuUSN-5432-1
HistoryMay 23, 2022 - 12:00 a.m.

libpng vulnerabilities

2022-05-2300:00:00
ubuntu.com
108
libpng
ubuntu 16.04 esm
denial of service
arbitrary code execution
png files
memory handling
cve-2017-12652
cve-2018-14048

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.032

Percentile

91.4%

Releases

  • Ubuntu 16.04 ESM

Packages

  • libpng - PNG (Portable Network Graphics) file library

Details

It was discovered that libpng incorrectly handled memory when parsing
certain PNG files. If a user or automated system were tricked into opening
a specially crafted PNG file, an attacker could use this issue to cause
libpng to crash, resulting in a denial of service, or possible execute
arbitrary code. (CVE-2017-12652)

Zhengxiong Luo discovered that libpng incorrectly handled memory when parsing
certain PNG files. If a user or automated system were tricked into opening
a specially crafted PNG file, an attacker could use this issue to cause
libpng to crash, resulting in a denial of service, or possible execute
arbitrary code. (CVE-2018-14048)

OSVersionArchitecturePackageVersionFilename
Ubuntu16.04noarchlibpng12-0< 1.2.54-1ubuntu1.1+esm1UNKNOWN
Ubuntu16.04noarchlibpng12-0< 1.2.54-1ubuntu1.1UNKNOWN
Ubuntu16.04noarchlibpng12-0-dbgsym< 1.2.54-1ubuntu1.1UNKNOWN
Ubuntu16.04noarchlibpng12-0-udeb< 1.2.54-1ubuntu1.1UNKNOWN
Ubuntu16.04noarchlibpng12-0-udeb-dbgsym< 1.2.54-1ubuntu1.1UNKNOWN
Ubuntu16.04noarchlibpng12-dev< 1.2.54-1ubuntu1.1UNKNOWN
Ubuntu16.04noarchlibpng3< 1.2.54-1ubuntu1.1UNKNOWN
Ubuntu16.04noarchlibpng12-dev< 1.2.54-1ubuntu1.1+esm1UNKNOWN
Ubuntu16.04noarchlibpng3< 1.2.54-1ubuntu1.1+esm1UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.032

Percentile

91.4%