Input validation error in libpng - CVE-2017-12652

 

Input validation error in libpng - CVE-2017-12652

Published: July 15, 2019


Vulnerability identifier: #VU19180
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12652
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in libpng when checking the chuck length against the user limit. A remote attacker can supply a specially crafted PNG image and crash the affected application.


Affected software

libpng
Isolation Segment
VMware Tanzu Application Service for VMs
Ansible Automation Platform
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Basesystem Module
Ubuntu
openEuler
Tanzu Greenplum for Kubernetes
IBM Security Privileged Identity Manager
Secure Remote Services (SRS) Virtual Edition
libpng (Red Hat package)
libpng12-debugsource
libpng12-debuginfo
libpng12
libpng12-devel
libpng12-0-debuginfo
libpng12-0
libpng3 (Ubuntu package)
libpng12-dev (Ubuntu package)
libpng12-0 (Ubuntu package)
libpng15-15
libpng15-15-debuginfo
libpng15-debugsource
syslinux
syslinux-perl
syslinux-extlinux
syslinux-efi64
syslinux-devel
syslinux-debugsource
syslinux-debuginfo
syslinux-tftpboot
syslinux-nonlinux
syslinux-extlinux-nonlinux
MikTex
PanelView 800 2711R-T4T
PanelView 800 2711R-T7T
PanelView 800 2711R-T10T
IBM QRadar Network Security
VMware Tanzu Operations Manager
Red Hat OpenShift Container Platform
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)

How to mitigate CVE-2017-12652

Install updates from vendor's website.

libpng - update to 1.6.32
Tanzu Greenplum for Kubernetes - update to 2.0.0
Ansible Automation Platform - addressed in versions 1.0, 1.1, 1.2.4
libpng (Red Hat package) - update to 1.5.13-8.el7
MikTex - update to 2.9.7300
PanelView 800 2711R-T4T - update to 6.011
PanelView 800 2711R-T7T - update to 6.011
PanelView 800 2711R-T10T - update to 6.011
Secure Remote Services (SRS) Virtual Edition - update to 3.46.00.04
IBM QRadar Network Security - addressed in versions 5.4.0.13, 5.5.0.8
libpng12-debugsource - update to 1.2.57-12
libpng12-debuginfo - update to 1.2.57-12
libpng12 - update to 1.2.57-12
libpng12-devel - update to 1.2.57-12
libpng12-devel - update to 1.2.59-150000.4.11.1
libpng12-0-debuginfo - update to 1.2.59-150000.4.11.1
libpng12-0 - update to 1.2.59-150000.4.11.1
libpng12-debugsource - update to 1.2.59-150000.4.11.1
libpng3 (Ubuntu package) - update to 1.2.541ubuntu1.1+esm1
libpng12-dev (Ubuntu package) - update to 1.2.541ubuntu1.1+esm1
libpng12-0 (Ubuntu package) - update to 1.2.541ubuntu1.1+esm1
libpng15-15 - addressed in versions 1.5.22-10.4.1, 1.5.30-10.13.1
libpng15-15-debuginfo - addressed in versions 1.5.22-10.4.1, 1.5.30-10.13.1
libpng15-debugsource - addressed in versions 1.5.22-10.4.1, 1.5.30-10.13.1
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40
Red Hat OpenShift Container Platform - update to 4.3.40
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Unity Operating Environment (OE) - update to 5.0.3.0.5.014
syslinux - update to 6.04-16
syslinux-perl - update to 6.04-16
syslinux-extlinux - update to 6.04-16
syslinux-efi64 - update to 6.04-16
syslinux-devel - update to 6.04-16
syslinux-debugsource - update to 6.04-16
syslinux-debuginfo - update to 6.04-16
syslinux-tftpboot - update to 6.04-16
syslinux-nonlinux - update to 6.04-16
syslinux-extlinux-nonlinux - update to 6.04-16

External References

Related Security Bulletins