DEBIAN-CVE-2025-66293

Source
https://security-tracker.debian.org/tracker/CVE-2025-66293
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-66293.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2025-66293
Upstream
Downstream
Published
2025-12-03T21:15:53.060Z
Modified
2025-12-10T11:15:32.805378Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H CVSS Calculator
Summary
[none]
Details

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the pngsRGBbase[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.

References

Affected packages

Debian:11 / libpng1.6

Package

Name
libpng1.6
Purl
pkg:deb/debian/libpng1.6?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.37-3+deb11u1

Affected versions

1.*

1.6.37-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-66293.json"

Debian:12 / libpng1.6

Package

Name
libpng1.6
Purl
pkg:deb/debian/libpng1.6?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.39-2+deb12u1

Affected versions

1.*

1.6.39-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-66293.json"

Debian:13 / libpng1.6

Package

Name
libpng1.6
Purl
pkg:deb/debian/libpng1.6?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.48-1+deb13u1

Affected versions

1.*

1.6.48-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-66293.json"

Debian:14 / libpng1.6

Package

Name
libpng1.6
Purl
pkg:deb/debian/libpng1.6?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.52-1

Affected versions

1.*

1.6.48-1
1.6.49-1~exp1
1.6.50-1~exp1
1.6.50-1
1.6.51-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-66293.json"