Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-2501

23
FAUCET Score

CVE-2011-2501 is an out-of-bounds read vulnerability in the png_format_buffer function of libpng versions 1.0.x, 1.2.x, 1.4.x, and 1.5.x, affecting products like Canonical, Debian, and Fedora. This medium-severity vulnerability (CVSS 6.5) can be triggered remotely with low complexity via a crafted PNG image, leading to a denial of service (application crash). There is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage for this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.0, < 1.0.55CPE matchmatch criteria
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:*
>= 1.2.0, < 1.2.45CPE matchmatch criteria
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:*
>= 1.4.0, < 1.4.8CPE matchmatch criteria
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:*
>= 1.5.0, < 1.5.4CPE matchmatch criteria
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:*
14CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:14:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.48%
Probability of exploitation in next 30 days
EPSS Percentile
87.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0348 is in the 95th percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

microsoftpatch availablevia msrc
Product: azl3 syslinux 6.04-11 on Azure Linux 3.0Fixed in: 6.04-11
microsoftpatch availablevia msrc
Product: 16848-17084Fixed in: 6.04-11
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: libpng-2:1.2.46-1.el6_1
View patch

Vendor Advisories (2)

microsoft2011-Jul/CVE-2011-2501Moderate

The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a CVE-2004-0421 regression. NOTE: this is called an off-by-one error by some sources.

Jul 2, 2011
redhatCVE-2011-2501Moderate

libpng: regression of CVE-2004-0421 in 1.2.23+

Jun 7, 2011

References

libpng.git.sourceforge.net / git/gitweb.cgi
lists.fedoraproject.org / pipermail/package-announce/2011-July/062720.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2011-July/063118.html
Mailing ListThird Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
secunia.com / advisories/45046
Broken Link
secunia.com / advisories/45289
Broken Link
secunia.com / advisories/45405
Broken Link
secunia.com / advisories/45415
Broken Link
secunia.com / advisories/45460
Broken Link
secunia.com / advisories/45486
Broken Link
secunia.com / advisories/45492
Broken Link
secunia.com / advisories/49660
Broken Link
security.gentoo.org / glsa/glsa-201206-15.xml
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/68517
Third Party AdvisoryVDB Entry
slackware.com / security/viewer.php
Mailing ListPatchThird Party Advisory
sourceforge.net / mailarchive/forum.php
ExploitIssue TrackingThird Party Advisory
debian.org / security/2011/dsa-2287
Third Party Advisory
mandriva.com / security/advisories
Broken Link
openwall.com / lists/oss-security/2011/06/27/13
Mailing ListPatchThird Party Advisory
openwall.com / lists/oss-security/2011/06/28/16
Mailing ListPatchThird Party Advisory
redhat.com / support/errata/RHSA-2011-1105.html
Broken Link
securityfocus.com / bid/48474
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-1175-1
Third Party Advisory