Debian Security Advisory

DSA-2410-1 libpng -- integer overflow

Date Reported:
15 Feb 2012
Affected Packages:
libpng
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2011-3026.
More information:

Jueri Aedla discovered an integer overflow in the libpng PNG library, which could lead to the execution of arbitrary code if a malformed image is processed.

For the stable distribution (squeeze), this problem has been fixed in version 1.2.44-1+squeeze2.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your libpng packages.