Opened 10 months ago

Closed 10 months ago

Last modified 8 months ago

#22471 closed enhancement (fixed)

libpng-1.6.52

Reported by: zeckma Owned by: zeckma
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

This update fixes a security vulnerability:

  • CVE-2025-66293 (CVSS 7.1, High): Out-of-bounds read in png_image_read_composite when processing palette PNG images with partial transparency and gamma correction.

This vulnerability can be caused by valid PNG images, not just crafted ones.

Change History (3)

comment:1 by zeckma, 10 months ago

Fixed at dc3e25516ad6315106535c73c8ec352b460f89b8. Leaving open for SA issuing, which I shall take care of.

comment:2 by zeckma, 10 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-047 issued.

comment:3 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.