Debian Security Advisory

DSA-2446-1 libpng -- incorrect memory handling

Date Reported:
04 Apr 2012
Affected Packages:
libpng
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2011-3048.
More information:

It was discovered that incorrect memory handling in the png_set_text2() function of the PNG library could lead to the execution of arbitrary code.

For the stable distribution (squeeze), this problem has been fixed in version libpng_1.2.44-1+squeeze4.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your libpng packages.