DEBIAN-CVE-2025-66293

Source
https://security-tracker.debian.org/tracker/CVE-2025-66293
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-66293.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2025-66293
Upstream
Downstream
Published
2025-12-03T21:15:53Z
Modified
2026-09-01T16:06:20Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H CVSS Calculator
Summary
[none]
Details

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.

References

Affected packages

Debian:12 / libpng1.6

Package

Name
libpng1.6
Purl
pkg:deb/debian/libpng1.6?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.6.39-2+deb12u1

Affected versions

1.*
1.6.39-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-66293.json"

Debian:13 / libpng1.6

Package

Name
libpng1.6
Purl
pkg:deb/debian/libpng1.6?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.6.48-1+deb13u1

Affected versions

1.*
1.6.48-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-66293.json"

Debian:14 / libpng1.6

Package

Name
libpng1.6
Purl
pkg:deb/debian/libpng1.6?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.6.52-1

Affected versions

1.*
1.6.48-1
1.6.49-1~exp1
1.6.50-1~exp1
1.6.50-1
1.6.51-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-66293.json"