|
Family: Ubuntu Local Security Checks --> Category: infos
USN1-1 : PNG library vulnerabilities Vulnerability Scan
Vulnerability Scan Summary PNG library vulnerabilities
Detailed Explanation for this Vulnerability Test
Synopsis :
These remote packages are missing security patches :
- libpng10-0
- libpng10-dev
- libpng12-0
- libpng12-dev
- libpng2
- libpng2-dev
- libpng3
- libpng3-dev
Description :
Several integer overflow vulnerabilities were discovered in the PNG library.
These vulnerabilities could be exploited by a possible hacker by providing a
specially crafted PNG image which, when processed by the PNG library, could
result in the execution of program code provided by the attacker.
The PNG library is used by a variety of software packages for different
purposes, so the exact nature of the exposure will vary depending on the
software involved.
Solution :
Upgrade to :
- libpng10-0-1.0.15-6ubuntu1 (Ubuntu 4.10)
- libpng10-dev-1.0.15-6ubuntu1 (Ubuntu 4.10)
- libpng12-0-1.2.5.0-7ubuntu1 (Ubuntu 4.10)
- libpng12-dev-1.2.5.0-7ubuntu1 (Ubuntu 4.10)
- libpng2-1.0.15-6ubuntu1 (Ubuntu 4.10)
- libpng2-dev-1.0.15-6ubuntu1 (Ubuntu 4.10)
- libpng3-1.2.5.0-7ubuntu1 (Ubuntu 4.10)
- libpng3-dev-1.2.5.0-7ubuntu1 (Ubuntu 4.10)
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|