#22471 closed enhancement (fixed)
libpng-1.6.52
| Reported by: | zeckma | Owned by: | zeckma |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
This update fixes a security vulnerability:
- CVE-2025-66293 (CVSS 7.1, High): Out-of-bounds read in png_image_read_composite when processing palette PNG images with partial transparency and gamma correction.
This vulnerability can be caused by valid PNG images, not just crafted ones.
Note:
See TracTickets
for help on using tickets.

Fixed at dc3e25516ad6315106535c73c8ec352b460f89b8. Leaving open for SA issuing, which I shall take care of.