Integer overflow in Google Chrome - CVE-2011-3026

 

Integer overflow in Google Chrome - CVE-2011-3026

Published: February 16, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU44269
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-3026
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.


Affected software

Google Chrome
Amazon Linux AMI
Gentoo Linux
Fedora
SUSE Linux
openEuler
libpng10
libpng12-devel
libpng12
libpng12-debuginfo
libpng12-debugsource
syslinux
syslinux-perl
syslinux-extlinux
syslinux-efi64
syslinux-devel
syslinux-debugsource
syslinux-debuginfo
syslinux-tftpboot
syslinux-nonlinux
syslinux-extlinux-nonlinux
IBM Cognos Business Intelligence Server

How to mitigate CVE-2011-3026

Install update from vendor's website.

Google Chrome - update to 17.0.963.56
libpng10 - update to 1.0.57-1.el6
libpng12-devel - update to 1.2.57-11
libpng12 - update to 1.2.57-11
libpng12-debuginfo - update to 1.2.57-11
libpng12-debugsource - update to 1.2.57-11
syslinux - update to 6.04-16
syslinux-perl - update to 6.04-16
syslinux-extlinux - update to 6.04-16
syslinux-efi64 - update to 6.04-16
syslinux-devel - update to 6.04-16
syslinux-debugsource - update to 6.04-16
syslinux-debuginfo - update to 6.04-16
syslinux-tftpboot - update to 6.04-16
syslinux-nonlinux - update to 6.04-16
syslinux-extlinux-nonlinux - update to 6.04-16
IBM Cognos Business Intelligence Server - addressed in versions 8.4.1.1, 10.1.1.2, 10.1.2, 10.2.1

External References

Related Security Bulletins