Debian DSA-2287-1 : libpng - several vulnerabilities

medium Nessus プラグイン ID 55721
New! プラグインの深刻度には CVSS v3 が適用されるようになりました。

プラグインの深刻度は、デフォルトで CVSS v3 を使って計算されるように更新されました。プラグインに CVSS v3 スコアがない場合には、CVSS v2 を使って深刻度が計算されます。深刻度の表示設定は、[設定]のドロップダウンで切り替えができます。


The remote Debian host is missing a security-related update.


The PNG library libpng has been affected by several vulnerabilities.
The most critical one is the identified as CVE-2011-2690. Using this vulnerability, an attacker is able to overwrite memory with an arbitrary amount of data controlled by her via a crafted PNG image.

The other vulnerabilities are less critical and allow an attacker to cause a crash in the program (denial of service) via a crafted PNG image.


Upgrade the libpng packages.

For the oldstable distribution (lenny), this problem has been fixed in version 1.2.27-2+lenny5. Due to a technical limitation in the Debian archive processing scripts, the updated packages cannot be released in parallel with the packages for Squeeze. They will appear shortly.

For the stable distribution (squeeze), this problem has been fixed in version 1.2.44-1+squeeze1.



深刻度: Medium

ID: 55721

ファイル名: debian_DSA-2287.nasl

バージョン: 1.13

タイプ: local

エージェント: unix

公開日: 2011/7/29

更新日: 2021/1/11

依存関係: ssh_get_info.nasl



リスクファクター: Medium

スコア: 5.9


リスクファクター: Medium

Base Score: 6.8

Temporal Score: 5

ベクトル: AV:N/AC:M/Au:N/C:P/I:P/A:P

現状ベクトル: E:U/RL:OF/RC:C


CPE: p-cpe:/a:debian:debian_linux:libpng, cpe:/o:debian:debian_linux:5.0, cpe:/o:debian:debian_linux:6.0

必要な KB アイテム: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

エクスプロイトの容易さ: No known exploits are available

パッチ公開日: 2011/7/28


CVE: CVE-2011-2501, CVE-2011-2690, CVE-2011-2691, CVE-2011-2692

BID: 48474, 48618, 48660

DSA: 2287